In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a lo…
High CVSS 7.5
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the device pointer was valid. Additionally, the implementation utilized an in_dev_for_each_ifa_rcu loop to match the packet source address against local interface addresses. It assumed that packets from the same subnet should not see a decrement o…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/5d05de2f0928d81309a815ecc76d1a3ad72cbc16 Patch
- https://git.kernel.org/stable/c/711987ba281fd806322a7cd244e98e2a81903114 Patch
- https://git.kernel.org/stable/c/79b90a96688e521771fa6ed3dc7864b76b8df293 Patch
- https://git.kernel.org/stable/c/83fc5dd63455a779ea2dd0f7ffee3c920919d80b Patch
- https://git.kernel.org/stable/c/95be653a76793856ff8b2d8bd82c2943c23f5ca8 Patch
- https://git.kernel.org/stable/c/c996a90f3071cf43683e5423da31aadbe002b8b4 Patch
- https://git.kernel.org/stable/c/edc806f9122961f0d3819f7c69c14cccde31f277 Patch
- https://git.kernel.org/stable/c/f4de0777e4554a7de19c920accde6319dd530782 Patch
Timeline
- nvd_ingest NVD