In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo: release elements in clone only from destroy path
Clone already always provides a current view of the lookup table, use it
to destroy the set, otherwise it is possible to destroy elements twice.
This fix requires:
212ed75dc5fb ("netfilter: nf_tables: integrate pipapo into commit protocol")
which came after:
9827a0e6e23b ("netfilter: nft_set_pipapo: release elements in clone from abort path").
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2024-04-04 10:15
Updated : 2025-03-19 16:19
NVD link : CVE-2024-26809
Mitre link : CVE-2024-26809
CVE.ORG link : CVE-2024-26809
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
