Description In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent possible UAF in ip6_xmit()
If skb_expand_head() returns NULL, skb has been freed
and the associated dst/idev could also have been freed.
We must use rcu_read_lock() to prevent a possible UAF.
CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Exploitability: 1.8 | Impact: 5.9 Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages14 packages Show 9 more packages
🔴 Vulnerability Details12 OSV linux-azure, linux-azure-6.8 vulnerabilities ↗ 2025-01-09 ▶ OSV linux-azure-5.15 vulnerabilities ↗ 2025-01-09 ▶ OSV linux-hwe-6.8 vulnerabilities ↗ 2025-01-06 ▶ OSV linux-gkeop vulnerabilities ↗ 2024-12-12 ▶ OSV linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency vulnerabilities ↗ 2024-12-12 ▶ Show 7 more
📋 Vendor Advisories13 Ubuntu Linux kernel (Azure) vulnerabilities ↗ 2025-01-09 ▶ Ubuntu Linux kernel (Azure) vulnerabilities ↗ 2025-01-09 ▶ Ubuntu Linux kernel (HWE) vulnerabilities ↗ 2025-01-06 ▶ Ubuntu Linux kernel (GKE) vulnerabilities ↗ 2024-12-12 ▶ Ubuntu Linux kernel (NVIDIA) vulnerabilities ↗ 2024-12-12 ▶ Show 8 more