Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
net: psample: fix info leak in PSAMPLE_ATTR_DATA

In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA psample open codes nla_put() presumably to avoid wiping the data with 0s just to override it with packet data. This open coding is missing clearing the pad, however, each netlink attr is padded to 4B and data_len may not be divisible by 4B.

Affected products

Linux
  • <aedd02af1f8b0bceb7f42f5a21c41634ca9ed390
  • <4.11
  • <0d3ea2ccddda442077fc44f11d873209c97ec50b
  • <befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2
  • ==4.11
  • <e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9
  • <48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6
  • <a6cfb924ad74efce254e99c197d2e3863de70868
  • =<6.18.*
  • =<6.1.*
  • =<6.6.*
  • =<5.15.*
  • =<6.12.*
  • =<*
  • <794a0d8bdbb39e083ed42caccb86d687a9b53570
  • <7fe7e6949964aa8ee6305f09db2dc9eede977bb3
  • =<7.1.*
  • =<5.10.*