REDHAT-BUG-2324315: Medium severity red hat kernel-devel vulnerability
In the Linux kernel, the following vulnerability has been resolved:
xfrm: validate new SA's prefixlen using SA family when sel.family is unset
This expands the validation introduced in commit 07bf7908950a ("xfrm: Validate address prefix lengths in the xfrm selector.")
syzbot created an SA with usersa.sel.family = AFUNSPEC usersa.sel.prefixlens = 128 usersa.family = AFINET
Because of the AFUNSPEC selector, verifynewsainfo doesn't put limits on prefixlen{s,d}. But then copyfromuserstate sets x->sel.family to usersa.family (AFINET). Do the same conversion in verifynewsainfo before validating prefixlen{s,d}, since that's how prefixlen is going to be used later on.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2324315?
REDHAT-BUG-2324315 has been classified with high severity due to its potential impact on kernel-level operations.
How do I fix REDHAT-BUG-2324315?
To fix REDHAT-BUG-2324315, you should apply the latest kernel updates provided by Red Hat.
What systems are affected by REDHAT-BUG-2324315?
REDHAT-BUG-2324315 affects systems running vulnerable versions of the Linux kernel.
What does REDHAT-BUG-2324315 involve?
REDHAT-BUG-2324315 involves the validation of new Security Associations' prefix lengths in the Linux kernel.
Is there a workaround for REDHAT-BUG-2324315?
Currently, there are no recommended workarounds for REDHAT-BUG-2324315, and updating the kernel is advised.