packet: use consistent hard_header_len in TX_RING send path
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.2%
probabilidade de exploração
0.2%top 94% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_header_len in TX_RING send path
tpacket_snd() reads dev->hard_header_len independently for skb
allocation and header construction in tpacket_fill_skb(). Concurrent
netdevice reconfiguration can therefore make the reserved headroom
smaller than the amount later pushed, or make copylen - hard_header_len
negative.
Snapshot hard_header_len once before processing ring frames and use it
for the frame limit, headroom allocation, copy length, and skb
construction. Pass the snapshot to tpacket_fill_skb().
The separate SOCK_DGRAM consistency problem between hard_header_len and
header_ops->create is not addressed here.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/016763e829cac37b3234eace86fd0a4c560de4a7https://git.kernel.org/stable/c/21b5953e7494c16a42e6cd8cf110e18d13ae4a6bhttps://git.kernel.org/stable/c/27e068d1b35dbec10a3cf268887c94407be4badchttps://git.kernel.org/stable/c/2a73b2c37ee3060a880b53cd24783d93fc7be5f8https://git.kernel.org/stable/c/9c7e8ff48c377bef18c3d178748aea0575b69edehttps://git.kernel.org/stable/c/d48ea5c9c4c34dc0df621f0e39ed3a16b644621ahttps://git.kernel.org/stable/c/d85d2fd54e901637c81d847811e03c662aee13cdhttps://git.kernel.org/stable/c/e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2