In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: do not update comments from kernel-side hash adds mtype_resize() copies comment pointers with memcpy(), not the…
Info
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: do not update comments from kernel-side hash adds mtype_resize() copies comment pointers with memcpy(), not the comment objects themselves. During the window after an entry has been copied but before the table swap and backlog replay, the old table is still published for packet-side updates while the replacement-table entry already holds the same ip_set_comment_rcu pointer. If xt_SET --add-set ... --exist h…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2
- https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207
- https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a
- https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207
- https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a
Timeline
- nvd_ingest NVD