In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(…
High CVSS 7.5
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not guarantee. Use get_unaligned_be32() instead, which reads the value safely and already returns host byte order, so the htonl() on the comparison constant can be dropped. This matches the existing get_unaligned_be32() us…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/4abc1af7ac209c066f4e5dd75cdd56876e5829a9
- https://git.kernel.org/stable/c/7ecfa46a536578a7ed335ddf31a854127268c27c
- https://git.kernel.org/stable/c/d3bf9eae486490832bd08fd62ab0ac601f346bd4
Timeline
- nvd_ingest NVD