In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix possible UAF in ip6_finish_output2()
If skb_expand_head() returns NULL, skb has been freed
and associated dst/idev could also have been freed.
We need to hold rcu_read_lock() to make sure the dst and
associated idev are alive.
[
{
"product": "Linux",
"vendor": "Linux",
"defaultStatus": "unaffected",
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"programFiles": [
"net/ipv6/ip6_output.c"
],
"versions": [
{
"version": "5796015fa968",
"lessThan": "e891b36de161",
"status": "affected",
"versionType": "git"
},
{
"version": "5796015fa968",
"lessThan": "3574d28caf9a",
"status": "affected",
"versionType": "git"
},
{
"version": "5796015fa968",
"lessThan": "6ab6bf731354",
"status": "affected",
"versionType": "git"
},
{
"version": "5796015fa968",
"lessThan": "56efc2531967",
"status": "affected",
"versionType": "git"
},
{
"version": "5796015fa968",
"lessThan": "da273b377ae0",
"status": "affected",
"versionType": "git"
}
]
},
{
"product": "Linux",
"vendor": "Linux",
"defaultStatus": "affected",
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"programFiles": [
"net/ipv6/ip6_output.c"
],
"versions": [
{
"version": "5.14",
"status": "affected"
},
{
"version": "0",
"lessThan": "5.14",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "5.15.166",
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.1.107",
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.6.48",
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.10.7",
"lessThanOrEqual": "6.10.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.11",
"lessThanOrEqual": "*",
"status": "unaffected",
"versionType": "original_commit_for_fix"
}
]
}
]
git.kernel.org/stable/c/3574d28caf9a09756ae87ad1ea096c6f47b6101e
git.kernel.org/stable/c/56efc253196751ece1fc535a5b582be127b0578a
git.kernel.org/stable/c/6ab6bf731354a6fdbaa617d1ec194960db61cf3b
git.kernel.org/stable/c/da273b377ae0d9bd255281ed3c2adb228321687b
git.kernel.org/stable/c/e891b36de161fcd96f12ff83667473e5067b9037