In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst The br_netfilter fake rtable is embedded in struct net_bridge…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst The br_netfilter fake rtable is embedded in struct net_bridge and is attached to bridged packets with skb_dst_set_noref(). If such a packet is queued to NFQUEUE, __nf_queue() upgrades that fake dst with skb_dst_force(). At that point the queued skb can hold a real dst reference after bridge teardown has started. The problem is not that every bridged packet n…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/01ace27af47801dd7f6b839e782b62863af979cc
- https://git.kernel.org/stable/c/0ca505346c5e2905ab7b5313af801fcf38f594a8
- https://git.kernel.org/stable/c/3f03a2d225c668283110ad5f9ff159ba4591e2c7
- https://git.kernel.org/stable/c/430521af7fe8a9c08f5a2554224a35f11f51d99e
- https://git.kernel.org/stable/c/47b3af24de5fbed4bf2952de0f5294ef1a338a26
- https://git.kernel.org/stable/c/8dc51351472825500145eed5bddfb88b2ec32008
- https://git.kernel.org/stable/c/c9c9b37f8c5505224e8d206184df3bb668ee00cf
Timeline
- nvd_ingest NVD