In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't leak bad clone into future transaction On memory allocation failure the cloned nft_pipapo_match …
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't leak bad clone into future transaction On memory allocation failure the cloned nft_pipapo_match can enter a bad state: - some fields can have their lookup tables resized while others did not - bits might have been toggled - scratch map can be undersized which also means m->bsize_max can be lower than what is required This means that the next insertion in the same batch can trigger ou…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/02b6b0e892aea582590671796fd6eff5b93ea93f
- https://git.kernel.org/stable/c/047e813324eac2ac60cddfb58bcdbd0144eadb09
- https://git.kernel.org/stable/c/0ab7b1802f63ca5b288ea59acb467830b83abd6b
- https://git.kernel.org/stable/c/47e65eff50691f0a5b79d325e28d83ec1da43bcf
- https://git.kernel.org/stable/c/610e3b73efaec3dd81a95dcda2421ad7d9795bd0
- https://git.kernel.org/stable/c/cc53703f48558896295f565cd4f5e956d21b7af4
- https://git.kernel.org/stable/c/e74f9680e1b64872a51cc7b5bda1edaaa08aa51f
Timeline
- nvd_ingest NVD