[SRU][Xenial][PATCH 0/1] CVE-2022-1016

Yuxuan Luo yuxuan.luo at canonical.com
Thu Feb 23 23:00:39 UTC 2023


[Impact]
David Bouman discovered that the netfilter subsystem in the Linux kernel
did not initialize memory in some situations. A local attacker could use
this to expose sensitive information

[Backport]
It's a clean cherry-pick.

[Test]
Compile and smoke tested.

[Potential Regression]
Expecting low risk of regression.

Pablo Neira Ayuso (1):
  netfilter: nf_tables: initialize registers in nft_do_chain()

 net/netfilter/nf_tables_core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

-- 
2.34.1




More information about the kernel-team mailing list