In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skb…
High CVSS 8.8
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skbs referencing the same nf_conn entry, which will happen for multicast (broadcast) frames on bridges. Example: macvlan0 | br0 / \ ethX ethY ethX (or Y) receives a L2 multicast or broadcast packet containing an IP packet, flow is not yet in conntrack table. 1. skb pa…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/2b1414d5e94e477edff1d2c79030f1d742625ea0 Patch
- https://git.kernel.org/stable/c/62e7151ae3eb465e0ab52a20c941ff33bb6332e9 Patch
- https://git.kernel.org/stable/c/7c3f28599652acf431a2211168de4a583f30b6d5 Patch
- https://git.kernel.org/stable/c/80cd0487f630b5382734997c3e5e3003a77db315 Patch
- https://git.kernel.org/stable/c/cb734975b0ffa688ff6cc0eed463865bf07b6c01 Patch
- https://git.kernel.org/stable/c/2b1414d5e94e477edff1d2c79030f1d742625ea0 Patch
- https://git.kernel.org/stable/c/62e7151ae3eb465e0ab52a20c941ff33bb6332e9 Patch
- https://git.kernel.org/stable/c/7c3f28599652acf431a2211168de4a583f30b6d5 Patch
- https://git.kernel.org/stable/c/80cd0487f630b5382734997c3e5e3003a77db315 Patch
- https://git.kernel.org/stable/c/cb734975b0ffa688ff6cc0eed463865bf07b6c01 Patch
Timeline
- nvd_ingest NVD