First published: Fri Jan 12 2024(Updated: )
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access.
Credit: security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=4.16<4.19.305 | |
Linux Linux kernel | >=4.20<5.4.267 | |
Linux Linux kernel | >=5.5<5.10.208 | |
Linux Linux kernel | >=5.11<5.15.147 | |
Linux Linux kernel | >=5.16<5.18 | |
Debian Debian Linux | =10.0 | |
redhat/kernel | <5.18 | 5.18 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.106-3 6.1.112-1 6.10.11-1 6.11.2-1 |
If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.