Last updated 25 March 2026
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
========== 1. Null-ptr-deref in xfrmupdateaeparams() ==========
[require privilege]: CAPNETADMIN
[effects]: local DoS
[crash stack]: [ 47.933119] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 47.933119] #PF: supervisor write access in kernel mode [ 47.933119] #PF: errorcode(0x0002) - not-present page [ 47.933119] PGD 8253067 P4D 8253067 PUD 8e0e067 PMD 0 [ 47.933119] Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI [ 47.933119] CPU: 0 PID: 98 Comm: poc.npd Not tainted 6.4.0-rc7-00072-gdad9774deaf1 #8 [ 47.933119] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.o4 [ 47.933119] RIP: 0010:memcpyorig+0xad/0x140 [ 47.933119] Code: e8 4c 89 5f e0 48 8d 7f e0 73 d2 83 c2 20 48 29 d6 48 29 d7 83 fa 10 72 34 4c 8b 06 4c 8b 4e 08 c [ 47.933119] RSP: 0018:ffff888008f57658 EFLAGS: 00000202 [ 47.933119] RAX: 0000000000000000 RBX: ffff888008bd0000 RCX: ffffffff8238e571 [ 47.933119] RDX: 0000000000000018 RSI: ffff888007f64844 RDI: 0000000000000000 [ 47.933119] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 [ 47.933119] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888008f57818 [ 47.933119] R13: ffff888007f64aa4 R14: 0000000000000000 R15: 0000000000000000 [ 47.933119] FS: 00000000014013c0(0000) GS:ffff88806d600000(0000) knlGS:0000000000000000 [ 47.933119] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 47.933119] CR2: 0000000000000000 CR3: 00000000054d8000 CR4: 00000000000006f0 [ 47.933119] Call Trace: [ 47.933119] <TASK> [ 47.933119] ? die+0x1f/0x70 [ 47.933119] ? pagefaultoops+0x1e8/0x500 [ 47.933119] ? pfxisprefetch.constprop.0+0x10/0x10 [ 47.933119] ? pfxpagefaultoops+0x10/0x10 [ 47.933119] ? rawspinunlockirqrestore+0x11/0x40 [ 47.933119] ? fixupexception+0x36/0x460 [ 47.933119] ? rawspinunlockirqrestore+0x11/0x40 [ 47.933119] ? excpagefault+0x5e/0xc0 [ 47.933119] ? asmexcpagefault+0x26/0x30 [ 47.933119] ? xfrmupdateaeparams+0xd1/0x260 [ 47.933119] ? memcpyorig+0xad/0x140 [ 47.933119] ? pfxrawspinlockbh+0x10/0x10 [ 47.933119] xfrmupdateaeparams+0xe7/0x260 [ 47.933119] xfrmnewae+0x298/0x4e0 [ 47.933119] ? pfxxfrmnewae+0x10/0x10 [ 47.933119] xfrmuserrcvmsg+0x25a/0x410 [ 47.933119] ? pfxxfrmuserrcvmsg+0x10/0x10 [ 47.933119] ? allocskb+0xcf/0x210 [ 47.933119] ? stacktracesave+0x90/0xd0 [ 47.933119] ? filterirqstacks+0x1c/0x70 [ 47.933119] ? stackdepotsave+0x39/0x4e0 [ 47.933119] ? kasanslabfree+0x10a/0x190 [ 47.933119] ? kmemcachefree+0x9c/0x340 [ 47.933119] ? netlinkrecvmsg+0x23c/0x660 [ 47.933119] ? sockrecvmsg+0xeb/0xf0 [ 47.933119] ? sysrecvfrom+0x13c/0x1f0 [ 47.933119] ? x64sysrecvfrom+0x71/0x90 [ 47.933119] ? dosyscall64+0x3f/0x90 [ 47.933119] ? entrySYSCALL64afterhwframe+0x72/0xdc [ 47.933119] ? copyout+0x3e/0x50 [ 47.933119] netlinkrcvskb+0xd6/0x210 [ 47.933119] ? pfxxfrmuserrcvmsg+0x10/0x10 [ 47.933119] ? pfxnetlinkrcvskb+0x10/0x10 [ 47.933119] ? pfxsockhasperm+0x10/0x10 [ 47.933119] ? mutexlock+0x8d/0xe0 [ 47.933119] ? pfxmutexlock+0x10/0x10 [ 47.933119] xfrmnetlinkrcv+0x44/0x50 [ 47.933119] netlinkunicast+0x36f/0x4c0 [ 47.933119] ? pfxnetlinkunicast+0x10/0x10 [ 47.933119] ? netlinkrecvmsg+0x500/0x660 [ 47.933119] netlinksendmsg+0x3b7/0x700 [ 47.933119] ? pfxnetlinksendmsg+0x10/0x10 [ 47.933119] ? updateloadavg+0x591/0xab0 [ 47.933119] ? pfxnetlinksendmsg+0x10/0x10 [ 47.933119] socksendmsg+0xde/0xe0 [ 47.933119] syssendto+0x18d/0x230 [ 47.933119] ? pfxsyssendto+0x10/0x10 [ 47.933119] ? rbinsertcolor+0x1c0/0x280 [ 47.933119] ? timerqueueadd+0x128/0x150 [ 47.933119] ? ktimeget+0x49/0xb0 [ 47.933119] ? pfxnativeapicmemwrite+0x10/0x10 [ 47.933119] ? lapicnextevent+0x35/0x40 [ 47.933119] ? clockeventsprogramevent+0xdf/0x140 [ 47.933119] ? hrtimerinterrupt+0x321/0x360 [ 47.933119] x64syssendto+0x71/0x90 [ 47.933119] dosyscall64+0x3f/0x90 [ 47.933119] entrySYSCALL64afterhwframe+0x72/0xdc [ 47.933119] RIP: 0033:0x44b8aa [ 47.933119] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 9 [ 47.933119] RSP: 002b:00007fff7ded8258 EFLAGS: 00000246 ORIGRAX: 000000000000002c [ 47.933119] RAX: ffffffffffffffda RBX: 00007fff7ded9688 RCX: 000000000044b8aa [ 47.933119] RDX: 00000000000002a8 RSI: 00007fff7ded8480 RDI: 0000000000000003 [ 47.933119] RBP: 00007fff7ded82c0 R08: 00007fff7ded829c R09: 000000000000000c [ 47.933119] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 47.933119] R13: 00007fff7ded9678 R14: 00000000004c37d0 R15: 0000000000000001 [ 47.933119] </TASK> [ 47.933119] Modules linked in: [ 47.933119] CR2: 0000000000000000 [ 47.933119] ---[ end trace 0000000000000000 ]--- [ 47.933119] RIP: 0010:memcpyorig+0xad/0x140 [ 47.933119] Code: e8 4c 89 5f e0 48 8d 7f e0 73 d2 83 c2 20 48 29 d6 48 29 d7 83 fa 10 72 34 4c 8b 06 4c 8b 4e 08 c [ 47.933119] RSP: 0018:ffff888008f57658 EFLAGS: 00000202 [ 47.933119] RAX: 0000000000000000 RBX: ffff888008bd0000 RCX: ffffffff8238e571 [ 47.933119] RDX: 0000000000000018 RSI: ffff888007f64844 RDI: 0000000000000000 [ 47.933119] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 [ 47.933119] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888008f57818 [ 47.933119] R13: ffff888007f64aa4 R14: 0000000000000000 R15: 0000000000000000 [ 47.933119] FS: 00000000014013c0(0000) GS:ffff88806d600000(0000) knlGS:0000000000000000 [ 47.933119] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 47.933119] CR2: 0000000000000000 CR3: 00000000054d8000 CR4: 00000000000006f0 [ 47.933119] Kernel panic - not syncing: Fatal exception in interrupt [ 47.933119] Kernel Offset: disabled [ 47.933119] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---
[buggy commit]: d8647b79c3b7 ("xfrm: Add user interface for esn and big anti-replay windows")
[root cause]: x->replayesn and x->preplayesn should be allocated at xfrmallocreplaystateesn(...) in xfrmstateconstruct(..), and then the xfrmupdateaeparams(...) is okay to update them. However, the current implementation allows a malicious user to directly dereference the pointer and crash the kernel like above.
[PoC code]: see attachment poc1.c. I have tested it in ubuntu 22.04 and latest Linux with QEMU.
[suggest fix]: Add NULL check in xfrmupdateaeparams() like below:
@@ -628,7 +628,7 @@ static void xfrmupdateaeparams(struct xfrmstate x, struct nlattr attrs, struct nlattr rt = attrs[XFRMAREPLAYTHRESH]; struct nlattr mt = attrs[XFRMAMTIMERTHRESH];
- if (re) { + if (re && x->replayesn && x->preplayesn) { struct xfrmreplaystateesn replayesn;
It was discovered that websocket-extensions does not properly parse special headers. A remote attacker could use this issue to cause regex backtracking, resulting in a denial of service. (CVE-2020-7663)
Fabian Vogt discovered that Ark incorrectly handled symbolic links in tar archive files. An attacker could use this to construct a malicious tar archive that, when opened, would create files outside the extraction directory.
USN-4468-1 fixed a vulnerability in Bind. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind incorrectly handled certain truncated responses to a TSIG-signed request. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2020-8622)
It was discovered that Mutt incorrectly handled certain requests. An attacker could possibly use this issue to enable MITM attacks. (CVE-2020-14954) This update also address a regression caused in the last update USN-4401-1. It only affected Ubuntu 12.04 ESM, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 19.10.
It was discovered that libvirt incorrectly handled an active pool without a target path. A remote attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2020-10703) It was discovered that libvirt incorrectly handled memory when retrieving certain domain statistics. A remote attacker could possibly use this issue to cause libvirt to consume resources, resulting in a denial of service. This issue only affected Ubuntu 19.10. (CVE-2020-12430)
It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this to issue execute arbitrary scripts or HTML. (CVE-2018-0618) It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this issue to display arbitrary text on a web page. (CVE-2018-13796) It was discovered that Mailman incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-12137)
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Multiple security issues were discovered in tcpdump. A remote attacker could use these issues to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code.
Daniel Preussker discovered that Octavia incorrectly handled client certificate checking. A remote attacker on the management network could possibly use this issue to perform configuration changes and obtain sensitive information.
Erik Olof Gunnar Andersson discovered that OpenStack Neutron incorrectly handled certain security group rules in the iptables firewall module. An authenticated attacker could possibly use this issue to block further application of security group rules for other instances.
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.
It was discovered that a From address encoded with a null character is cut off in the message header display. An attacker could potentially exploit this to spoof the sender address. (CVE-2017-7829) It was discovered that it is possible to execute JavaScript in RSS feeds in some circumstances. If a user were tricked in to opening a specially crafted RSS feed, an attacker could potentially exploit this in combination with another vulnerability, in order to cause unspecified problems. (CVE-2017-7846) It was discovered that the RSS feed can leak local path names. If a user were tricked in to opening a specially crafted RSS feed, an attacker could potentially exploit this to obtain sensitive information. (CVE-2017-7847) It was discovered that RSS feeds are vulnerable to new line injection. If a user were tricked in to opening a specially crafted RSS feed, an attacker could potentially exploit this to cause unspecified problems. (CVE-2017-7848) Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, execute arbitrary code, or cause other unspecified effects. (CVE-2018-5089, CVE-2018-5095, CVE-2018-5096, CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5117)
It was discovered that libnl incorrectly handled memory when performing certain operations. A local attacker could possibly use this issue to cause libnl to crash, resulting in a denial of service, or execute arbitrary code.
A poison null byte flaw was found in the implementation of the DiskFileItem class. A remote attacker able to supply a serialized instance of the DiskFileItem class, which will be deserialized on a server, could use this flaw to write arbitrary content to any location on the server that is permitted by the user running the application server process.