REDHAT-BUG-1440788: Integer Overflow
An integer overflow vulnerability was found in nlmsgreserve() triggered by crafted @len argument resulting into reserving too few bytes.
Upstream patch:
http://git.infradead.org/users/tgr/libnl.git/commit/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1440788?
The severity of REDHAT-BUG-1440788 is classified as high due to the potential for exploitation through integer overflow.
How does REDHAT-BUG-1440788 affect the libnl library?
REDHAT-BUG-1440788 affects the libnl library by allowing an integer overflow that may lead to memory corruption and denial of service.
What is the impact of not addressing REDHAT-BUG-1440788?
Not addressing REDHAT-BUG-1440788 could result in application crashes and potential exploitation vectors for attackers.
How do I fix REDHAT-BUG-1440788?
To fix REDHAT-BUG-1440788, you should apply the upstream patch provided in the vulnerability report.
Is there a known exploit for REDHAT-BUG-1440788?
As of now, there are no widely reported exploits for REDHAT-BUG-1440788, but the vulnerability should still be remediated.