Kernel Live Patch Security Notice LSN-0101-1

Discussion in 'News Aggregator' started by Packet Storm, 8 Mar 2024.

  1. Packet Storm

    Packet Storm Guest

    Xingyuan Mo discovered that the netfilter subsystem in the Linux kernel did not properly handle inactive elements in its PIPAPO data structure, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. It was discovered that the IGMP protocol implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...