[SRU][Mantic][Lunar][PATCH 0/2] CVE-2023-5972

Bethany Jamison bethany.jamison at canonical.com
Mon Dec 4 17:45:25 UTC 2023


[Impact]

A null pointer dereference flaw was found in the nft_inner.c functionality
of netfilter in the Linux kernel. This issue could allow a local user to
crash the system or escalate their privileges on the system.

[Fix]

Clean cherry-picks.

[Test]

Compile and boot test.

[Where problems could occur]

Issues could occur in netfilter.

Xingyuan Mo (2):
  nf_tables: fix NULL pointer dereference in nft_inner_init()
  nf_tables: fix NULL pointer dereference in nft_expr_inner_parse()

 net/netfilter/nf_tables_api.c | 2 +-
 net/netfilter/nft_inner.c     | 1 +
 2 files changed, 2 insertions(+), 1 deletion(-)

-- 
2.34.1




More information about the kernel-team mailing list