In the Linux kernel, the following vulnerability has been resolved: xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING syzbot reported an illegal copy in xsk_setsockopt() [1] Make sure t…
High CVSS 7.1
Summary
In the Linux kernel, the following vulnerability has been resolved: xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING syzbot reported an illegal copy in xsk_setsockopt() [1] Make sure to validate setsockopt() @optlen parameter. [1] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in xsk_setsockopt+0x909/0xa40 net/…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/0b45c25d60e38f5c2cb6823f886773a34323306d Patch
- https://git.kernel.org/stable/c/237f3cf13b20db183d3706d997eedc3c49eacd44 Patch
- https://git.kernel.org/stable/c/2a523f14a3f53b46ff0e1fafd215b0bc5f6783aa Patch
- https://git.kernel.org/stable/c/2eb979fbb2479bcd7e049f2f9978b6590dd8a0e6 Patch
- https://git.kernel.org/stable/c/a82984b3c6a7e8c7937dba6e857ddf829d149417 Patch
- https://git.kernel.org/stable/c/b143e19dc28c3211f050f7848d87d9b0a170e10c Patch
- https://git.kernel.org/stable/c/beb99266830520e15fbc6ca8cc5a5240d76851fd Patch
- https://git.kernel.org/stable/c/f0a068de65d5b7358e9aff792716afa9333f3922 Patch
- https://git.kernel.org/stable/c/0b45c25d60e38f5c2cb6823f886773a34323306d Patch
- https://git.kernel.org/stable/c/237f3cf13b20db183d3706d997eedc3c49eacd44 Patch
- https://git.kernel.org/stable/c/2a523f14a3f53b46ff0e1fafd215b0bc5f6783aa Patch
- https://git.kernel.org/stable/c/2eb979fbb2479bcd7e049f2f9978b6590dd8a0e6 Patch
- https://git.kernel.org/stable/c/a82984b3c6a7e8c7937dba6e857ddf829d149417 Patch
- https://git.kernel.org/stable/c/b143e19dc28c3211f050f7848d87d9b0a170e10c Patch
- https://git.kernel.org/stable/c/beb99266830520e15fbc6ca8cc5a5240d76851fd Patch
- https://git.kernel.org/stable/c/f0a068de65d5b7358e9aff792716afa9333f3922 Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Timeline
- nvd_ingest NVD