摘要:
In the Linux kernel, the following vulnerability has been resolved:
net/tcp_ao: Don't leak ao_info on error-path
It seems I introduced it together with TCP_AO_CMDF_AO_REQUIRED, on
version 5 [1] of TCP-AO patches. Quite frustrative that having all these
selftests that I've written, running kmemtest & kcov was always in todo.
[1]: https://lore.kernel.org/netdev/20230215183335.800122-5-dima@arista.com/
安全等级: Low
公告ID: KylinSec-SA-2024-3317
发布日期: 2024年8月20日
关联CVE: CVE-2024-40985
In the Linux kernel, the following vulnerability has been resolved:
net/tcp_ao: Don't leak ao_info on error-path
It seems I introduced it together with TCP_AO_CMDF_AO_REQUIRED, on
version 5 [1] of TCP-AO patches. Quite frustrative that having all these
selftests that I've written, running kmemtest & kcov was always in todo.
[1]: https://lore.kernel.org/netdev/20230215183335.800122-5-dima@arista.com/
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-40985 | KY3.4-5A | kernel | Unaffected |
CVE-2024-40985 | KY3.5.3 | kernel | Unaffected |
CVE-2024-40985 | V6 | kernel | Unaffected |