In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check FLOWI_FLAG_KNOWN_NH on fl6->flowi6_flags instead of testing HDRINCL on the socket to avoid a race condition which causes uninit-value access.
En el kernel de Linux, se resolvió la siguiente vulnerabilidad: ipv6: corrige el posible acceso a valores uninit en __ip6_make_skb() Como se hizo en el commit fc1092f51567 ("ipv4: corrige el acceso a valores uninit en __ip_make_skb()") para IPv4, verifique FLOWI_FLAG_KNOWN_NH en fl6->flowi6_flags en lugar de probar HDRINCL en el socket para evitar una condición de ejecución que provoque acceso a valores uninit.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-908
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24246c3980> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a7f75dc0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424537d40> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23bea7a200> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23af2bf7c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59e85c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23af2bd280> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d2424536dc0> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d24246c2b00> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d23af2bc840> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d24246c1f40> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d24246c0f00> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d242455eac0> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d23bea78740> | Operating System |
| linux | linux_kernel | 6.9 | <built-in method update of dict object at 0x7d2424536a80> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.9:rc7:*:*:*:*:*:* |