netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
Sashiko pointed out that kfree_rcu() was called before
rcu_assign_pointer() in handling the comment extension.
Fix the order so that rcu_assign_pointer() called first.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/3ca9982a8882470aa0ac4e8bb9a552b181d1efcdhttps://git.kernel.org/stable/c/50b70f56f3baaff46599f59b2d93fa2540120776https://git.kernel.org/stable/c/6e98407cb94e035bba98956adc9096a76d8b2a9fhttps://git.kernel.org/stable/c/8087bb360a936a6314d22b567e4b861656943eb6https://git.kernel.org/stable/c/93a775fd67f3ef34949a9523bfa69403ee74efddhttps://git.kernel.org/stable/c/c9787d7c24ffd83019f379455e1b97fb4f0f75ebhttps://git.kernel.org/stable/c/d01b4b471f0fc5c396af62845e972ccf99cee29ahttps://git.kernel.org/stable/c/fcb565966534909377a16be5f7b065db2e25c8b5