发布时间: 2024年6月13日
修改时间: 2024年7月2日
In the Linux kernel, the following vulnerability has been resolved: net: mctp: take ownership of skb in mctp_local_output Currently, mctp_local_output only takes ownership of skb on success, and we may leak an skb if mctp_local_output fails in specific states; the skb ownership isn't transferred until the actual output routing occurs. Instead, make mctp_local_output free the skb on all error paths up to the route action, so it always consumes the passed skb.
NVD | openEuler | |
---|---|---|
Confidentiality | ||
Attack Vector | ||
CVSS评分 | N/A | N/A |
Attack Complexity | ||
Privileges Required | ||
Scope | ||
Integrity | ||
User Interaction | ||
Availability |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-2687 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: take ownership of skb in mctp_local_output Currently, mctp_local_output only takes ownership of skb on success, and we may leak an skb if mctp_local_output fails in specific states; the skb ownership isn't transferred until the actual output routing occurs. Instead, make mctp_local_output free the skb on all error paths up to the route action, so it always consumes the passed skb. | 2024年6月13日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5 | kernel | Unaffected |
KY3.5.2 | kernel | Unaffected |
KY3.5.3 | kernel | Unaffected |
V6 | kernel | Unaffected |