← Πίσω στην αναζήτηση CVE

CVE-2026-52998

Linux Kernel

Περιγραφή

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the device pointer was valid. Additionally, the implementation utilized an in_dev_for_each_ifa_rcu loop to match the packet source address against local interface addresses. It assumed that packets from the same subnet should not see a decrement on the initial TTL. A packet might appear it is from the same subnet but it actually isn-t especially in modern environments with containers and virtual switching. Remove the device dereference and interface loop. Replace the logic with a switch statement that evaluates the TTL according to the ttl_check.

CVSS 7.5EPSS 0.501%Κίνδυνος 0.78
Προβολή πηγής
Δημοσίευση
2026-06-24 17:17:10
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Πυρήνας
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Λειτουργικά συστήματα
Linux