Vulnerability CVE-2024-26855


Published: 2024-04-17

Description:
In the Linux kernel, the following vulnerability has been resolved:

net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink()

The function ice_bridge_setlink() may encounter a NULL pointer dereference
if nlmsg_find_attr() returns NULL and br_spec is dereferenced subsequently
in nla_for_each_nested(). To address this issue, add a check to ensure that
br_spec is not NULL before proceeding with the nested attribute iteration.

 References:
https://git.kernel.org/stable/c/d9fefc51133107e59d192d773be86c1150cfeebb
https://git.kernel.org/stable/c/37fe99016b12d32100ce670216816dba6c48b309
https://git.kernel.org/stable/c/8d95465d9a424200485792858c5b3be54658ce19
https://git.kernel.org/stable/c/afdd29726a6de4ba27cd15590661424c888dc596
https://git.kernel.org/stable/c/1a770927dc1d642b22417c3e668c871689fc58b3
https://git.kernel.org/stable/c/0e296067ae0d74a10b4933601f9aa9f0ec8f157f
https://git.kernel.org/stable/c/06e456a05d669ca30b224b8ed962421770c1496c

Copyright 2024, cxsecurity.com

 

Back to Top