[SRU OEM-5.10/Hirsute/Impish 0/1] CVE-2021-43267

Thadeu Lima de Souza Cascardo cascardo at canonical.com
Wed Nov 24 12:34:22 UTC 2021


CVE-2021-43267

[Impact]
An invalid TIPC message may cause out-of-bounds read and write.

[Test case]
There is no known test case.

[Potential regression]
Only TIPC is affected, and only messages of type MSG_CRYPTO should be
affected. This should be restricted to TIPC users.


Max VA (1):
  tipc: fix size validations for the MSG_CRYPTO type

 net/tipc/crypto.c | 32 +++++++++++++++++++++-----------
 1 file changed, 21 insertions(+), 11 deletions(-)

-- 
2.32.0




More information about the kernel-team mailing list