Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 day, 11 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
vxlan: re-fetch eth header after route_shortcircuit()

In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). Inside route_shortcircuit(), pskb_may_pull() can be called, which may reallocate skb->head. In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to freed memory, leading to a use-after-free when dereferencing eth->h_dest. Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().

Affected products

Linux
  • =<6.1.*
  • <c9dceac9e1c7c772c43c732fc0d325e72835801a
  • <2355c8c26d2aa1b4385b369e67202e47d460d555
  • <bf045341dfb3e767f0ff94cf240ce3c371973bd4
  • <1511631b7cfc4152b10a0a9d04c7a0bf2ddf4585
  • =<5.10.*
  • <1235e017aa11cf01e91b613c4c5ed6aa28934fff
  • =<6.18.*
  • =<6.6.*
  • =<6.12.*
  • =<7.1.*
  • <1b7f7b653e3557690047c62f03b80a24ea5a58a5
  • <1395a676ec15a0a02a2a6d86602324f2d5fd41d5
  • =<5.15.*
  • <6375093eb45cd7d89f1945f939eeae3b29d79f56
  • <3.10
  • =<*
  • ==3.10