In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer is initialized to …
Info
Summary
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer is initialized to point into the skb's linear data buffer. Later, the code calls skb_ensure_writable(), which might reallocate the buffer: if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) goto drop; /* Trace pointer may have changed */ trace = (struct ioam6_trace_hdr *)(skb_network_header(skb) …
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/24de676da63c1122d2c13b0d546238b66d1b4e62
- https://git.kernel.org/stable/c/5af905aa8e91ff8d94572a1e089558f21dcf24ed
- https://git.kernel.org/stable/c/769723124b7c3b2bfea4cf68ad292698b87c8d01
- https://git.kernel.org/stable/c/e46e6bc97fb1f339730ff1ba74267fbf48e7a422
Timeline
- nvd_ingest NVD