In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to the master conntrack is unsafe. Use exp->master->helper in ctnetlink path if userspace does not provide an explicit helper when creating an expectation to retain the existing behaviour. The ctnetlink expectation path holds the reference on the master conntrack and nf_conntrack_expect lock and the nfnetlink glue path refers to the master ct that is attached to the skb.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Type: Secondary
Exploitability Score: 3.9
Impact Score: 5.9
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59fde80> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59ff640> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59fe940> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24246c00c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59fe1c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a59ff200> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a59fdbc0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2424609bc0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24246c03c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a59fda80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23bea8a9c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* |