In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: clone set element expression template memcpy() breaks when using connlimit in set elements. Use nft_expr_clo…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: clone set element expression template memcpy() breaks when using connlimit in set elements. Use nft_expr_clone() to initialize the connlimit expression list, otherwise connlimit garbage collector crashes when walking on the list head copy. [ 493.064656] Workqueue: events_power_efficient nft_rhash_gc [nf_tables] [ 493.064685] RIP: 0010:find_or_evict+0x5a/0x90 [nf_conncount] [ 493.064694] Code: 2b 43 40…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/47d8de3c226574a3ddb8b87d0c152028d1bafef4 Patch
- https://git.kernel.org/stable/c/4d8f9065830e526c83199186c5f56a6514f457d2 Patch
- https://git.kernel.org/stable/c/e51ff3ffc316377cca21de8b80404eed0c37b3c3 Patch
- https://git.kernel.org/stable/c/47d8de3c226574a3ddb8b87d0c152028d1bafef4 Patch
- https://git.kernel.org/stable/c/4d8f9065830e526c83199186c5f56a6514f457d2 Patch
- https://git.kernel.org/stable/c/e51ff3ffc316377cca21de8b80404eed0c37b3c3 Patch
Timeline
- nvd_ingest NVD