See how linux compares to other vendors in security performance
In the Linux kernel, the following vulnerability has been resolved:
xfrm: ah6: validate routing header segmentsleft
AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6rearrangerthdr() assumes that segmentsleft is not larger than the number of addresses described by the routing header's hdrlen field.
That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segmentsleft value. With segmentsleft equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access.
Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths.