net: psample: fix info leak in PSAMPLE_ATTR_DATA
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 93% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
net: psample: fix info leak in PSAMPLE_ATTR_DATA
psample open codes nla_put() presumably to avoid wiping
the data with 0s just to override it with packet data.
This open coding is missing clearing the pad, however,
each netlink attr is padded to 4B and data_len may
not be divisible by 4B.
Productos afectados
Linux · LinuxReferencias
https://git.kernel.org/stable/c/0d3ea2ccddda442077fc44f11d873209c97ec50bhttps://git.kernel.org/stable/c/48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6https://git.kernel.org/stable/c/794a0d8bdbb39e083ed42caccb86d687a9b53570https://git.kernel.org/stable/c/7fe7e6949964aa8ee6305f09db2dc9eede977bb3https://git.kernel.org/stable/c/a6cfb924ad74efce254e99c197d2e3863de70868https://git.kernel.org/stable/c/aedd02af1f8b0bceb7f42f5a21c41634ca9ed390https://git.kernel.org/stable/c/befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2https://git.kernel.org/stable/c/e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9