In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error in bridge device's x…
高危 CVSS 7.3
摘要
In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error in bridge device's xmit path by sending a short (less than ETH_HLEN bytes) skb. To fix it check if we can actually pull that amount instead of assuming. Tested with dropwatch: drop at: br_dev_xmit+0xb93/0x12d0 [bridge] (0xffffffffc06739b3) origin: software timestamp: Mon May 13 11:31:53 2024 778214037 nsec protoco…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/1abb371147905ba250b4cc0230c4be7e90bea4d5 Patch
- https://git.kernel.org/stable/c/28126b83f86ab9cc7936029c2dff845d3dcedba2 Patch
- https://git.kernel.org/stable/c/3e01fc3c66e65d9afe98f1489047a1b2dd8741ca
- https://git.kernel.org/stable/c/5b5d669f569807c7ab07546e73c0741845a2547a Patch
- https://git.kernel.org/stable/c/82090f94c723dab724b1c32db406091d40448a17
- https://git.kernel.org/stable/c/8bd67ebb50c0145fd2ca8681ab65eb7e8cde1afc Patch
- https://git.kernel.org/stable/c/b2b7c43cd32080221bb233741bd6011983fe7c11
- https://git.kernel.org/stable/c/c964429ef53f42098a6545a5dabeb1441c1e821d
- https://git.kernel.org/stable/c/f482fd4ce919836a49012b2d31b00fc36e2488f2 Patch
- https://git.kernel.org/stable/c/1abb371147905ba250b4cc0230c4be7e90bea4d5 Patch
- https://git.kernel.org/stable/c/28126b83f86ab9cc7936029c2dff845d3dcedba2 Patch
- https://git.kernel.org/stable/c/5b5d669f569807c7ab07546e73c0741845a2547a Patch
- https://git.kernel.org/stable/c/8bd67ebb50c0145fd2ca8681ab65eb7e8cde1afc Patch
- https://git.kernel.org/stable/c/f482fd4ce919836a49012b2d31b00fc36e2488f2 Patch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
时间线
- nvd_ingest NVD