In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a5978dc0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a5979e40> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a597aa40> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24604c2300> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a59799c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a5979640> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a5979780> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24246e6b00> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a5978ac0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a597be00> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a5979a80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a597a800> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23af181dc0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* |