In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_mirred: don't override retval if we already lost the skb
If we're redirecting the skb, and haven't called tcf_mirred_forward(),
yet, we need to tell the core to drop the skb by setting the retcode
to SHOT. If we have called tcf_mirred_forward(), however, the skb
is out of our hands and returning SHOT will lead to UaF.
Move the retval override to the error path which actually need it.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-04-03 17:15
Updated : 2025-11-25 17:29
NVD link : CVE-2024-26739
Mitre link : CVE-2024-26739
CVE.ORG link : CVE-2024-26739
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-416
Use After Free
