Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 2 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
udp: fix potential use-after-free in tunnel segmentation

In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid. Get the UDP header after the pull to avoid a potential use-after-free.

Affected products

Linux
  • <19d89b13a43640b2da2f277ee462d919d988cb6f
  • <588d4a6795d99d080f74ef0b5f391ea8c453ae5d
  • <b3df61bb745eb5201eac22679a2839d4ccbf3442
  • <5161e67c561c4f28a5d9335a6e859b02511de92b
  • ==4.6
  • <4.6
  • <64d322c288577793eedd352b96ef75234ed380fe
  • =<5.15.*
  • =<6.6.*
  • =<7.1.*
  • =<5.10.*
  • <1ae134c012e10384cdac420b5cc6e0615cde0b55
  • =<6.18.*
  • =<6.1.*
  • <6a733a38b983d8c2e222f13968209010cf44de87
  • <d0f86fb36eb260abd10007b62c9dcc1028e03e61
  • =<6.12.*
  • =<*