[N:linux][PATCH 0/1] netlink: terminate outstanding dump on socket close
Philip Cox
philip.cox at canonical.com
Fri Feb 28 20:52:02 UTC 2025
CVE-2024-53140
SRU Justification:
[Impact]
A local user can potentially cause a use-after-free by winning a race condition in the netlink code path.
[Backport]
The Fix was cherry-picked from upstream commit 1904fb9ebf911441f90a68e96b22aa73e4410505
[Test]
compile and boot tested.
[Where problems could occur]
If any back ports are added that assume the old behaviour, it could cause them to fail, but the risk is very low, and the window of change is fairly narrow.
--
More information about the kernel-team
mailing list