In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector facility Currently csum_partial() calls csum_copy() with copy=false and dst=NULL…
Critical CVSS 9.8
Summary
In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector facility Currently csum_partial() calls csum_copy() with copy=false and dst=NULL. On machines without the vector facility, csum_copy() falls back to cksm(dst, ...), causing the checksum to be calculated from address zero instead of the source buffer. The VX implementation already checksums data loaded from src. Make the fallback do the same by passing src to cksm().
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/1d9a2f01b3c4e5c88e06b2db4b5460c2ec884722
- https://git.kernel.org/stable/c/4bb06b60d982355e22647b3d12d6619419f8c1fa
- https://git.kernel.org/stable/c/5fc0a2a6eeb99cac991242bb48796c7749ce3261
- https://git.kernel.org/stable/c/898bb2814f38399108bdd2113f38d97383a7036a
Timeline
- nvd_ingest NVD