xfrm: validate selector family and prefixlen during match
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
xfrm: validate selector family and prefixlen during match
syzbot reported a shift-out-of-bounds in xfrm_selector_match()
due to AF_UNSPEC selector with large prefixlen (e.g. 128) matched
against IPv4 flow (when XFRM_STATE_AF_UNSPEC is set).
Fix this by:
- Rejecting mismatched families in xfrm_selector_match.
- Returning false in addr4_match if prefixlen > 32.
- Returning false in addr_match if prefixlen > 128 (prevents overflow).
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/40f0b1047918539f0b0f795ac65e35336b4c2c78https://git.kernel.org/stable/c/5a03a2ee17e8259dde631ed84fd8322db06cb2aehttps://git.kernel.org/stable/c/6d99379c58f7f1c6ab2cc7aba01a4f52d71adcfehttps://git.kernel.org/stable/c/78783fefdc8f36879b1a17efa0d3195ea5f2dc5fhttps://git.kernel.org/stable/c/87a5bbccc7ff4edb3f42fea387124237d2ba91eehttps://git.kernel.org/stable/c/a3968ad4195d72c8fddcc6c0ef39da95ac98711ahttps://git.kernel.org/stable/c/bd7f202cf77556cff59f68dc30e4cdf40cb6e33bhttps://git.kernel.org/stable/c/efa9e3b9f3dea2e1ea4c7edf4edc863faef85986