xfrm: Fix skb double-free in xfrm_dev_direct_output()
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.8epss 0.5%
probabilidade de exploração
0.5%top 61% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Fix skb double-free in xfrm_dev_direct_output()
A return value other than 1 from local_out() means that the skb has been
consumed or its ownership was transferred. xfrm_dev_direct_output()
nevertheless frees the skb on this path, causing a double-free when
netfilter drops the packet and invalidating any other owner.
Return the local_out() result directly, matching the ownership handling
in xfrm_output_resume().
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/02deb637e965950148752a304dd1471212dd6470https://git.kernel.org/stable/c/2aed51fc58d9ce450e2c116efb956160fd06fa02https://git.kernel.org/stable/c/56a347950e661c1a7f8f31c43a2ea53c2323b6f4https://git.kernel.org/stable/c/621871b696b108026bf4b44ed4085ffa2102f417https://git.kernel.org/stable/c/bc9297796bfdcc8d9609236e54519a4f38737aac