In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag skbs in fraglist with the original head …
高危 CVSS 7.8
摘要
In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag skbs in fraglist with the original head skb. It's not safe to access these frag skbs. syzbot reported two use-of-uninitialized-memory bugs caused by this: BUG: KMSAN: uninit-value in sctp_inq_pop+0x15b7/0x1920 net/sctp/inqueue.c:211 sctp_inq_pop+0x15b7/0x1920 net/sctp/inqueue.c:211 sctp_assoc_bh_rcv+0x1a7/0xc50 net/sctp/associol…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/03d0cc6889e02420125510b5444b570f4bbf53d5 Patch
- https://git.kernel.org/stable/c/1bd5214ea681584c5886fea3ba03e49f93a43c0e Patch
- https://git.kernel.org/stable/c/4506bcaabe004d07be8ff09116a3024fbd6aa965 Patch
- https://git.kernel.org/stable/c/7d757f17bc2ef2727994ffa6d5d6e4bc4789a770 Patch
- https://git.kernel.org/stable/c/cd0e92bb2b7542fb96397ffac639b4f5b099d0cb Patch
- https://git.kernel.org/stable/c/d0194e391bb493aa6cec56d177b14df6b29188d5 Patch
- https://git.kernel.org/stable/c/ea094f38d387d1b0ded5dee4a3e5720aa4ce0139 Patch
- https://git.kernel.org/stable/c/fc66772607101bd2030a4332b3bd0ea3b3605250 Patch
- https://git.kernel.org/stable/c/fd60d8a086191fe33c2d719732d2482052fa6805 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Mailing List
时间线
- nvd_ingest NVD