summaryrefslogtreecommitdiffstats
path: root/active/CVE-2024-26641
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2024-03-18 18:04:48 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2024-03-18 18:04:48 +0100
commitbcd9eccef0863578591f91cfde157a7c1fcf4d9e (patch)
tree51bcfe848aef821a7b1a16ad6c272fc86e25630e /active/CVE-2024-26641
parent602dff7a3e25bb7b7271a9400d5ff4ce861d05c0 (diff)
Add new batch of CVEs
Fixup for fix in earlier versions as 6.6.15-1 and one N/A as vulnerable code was only introduced in 6.7 series.
Diffstat (limited to 'active/CVE-2024-26641')
-rw-r--r--active/CVE-2024-2664116
1 files changed, 16 insertions, 0 deletions
diff --git a/active/CVE-2024-26641 b/active/CVE-2024-26641
new file mode 100644
index 00000000..bfc28395
--- /dev/null
+++ b/active/CVE-2024-26641
@@ -0,0 +1,16 @@
+Description: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()
+References:
+Notes:
+ carnil> Introduced in 0d3c703a9d17 ("ipv6: Cleanup IPv6 tunnel receive path").
+ carnil> Vulnerable versions: 4.7-rc1.
+Bugs:
+upstream: released (6.8-rc3) [8d975c15c0cd744000ca386247432d57b21f9df0]
+6.7-upstream-stable: released (6.7.4) [c835df3bcc14858ae9b27315dd7de76370b94f3a]
+6.6-upstream-stable: released (6.6.16) [350a6640fac4b53564ec20aa3f4a0922cb0ba5e6]
+6.1-upstream-stable: released (6.1.77) [d54e4da98bbfa8c257bdca94c49652d81d18a4d8]
+5.10-upstream-stable: released (5.10.210) [a9bc32879a08f23cdb80a48c738017e39aea1080]
+4.19-upstream-stable: needed
+sid: released (6.7.7-1)
+6.1-bookworm-security: needed
+5.10-bullseye-security: needed
+4.19-buster-security: needed

© 2014-2024 Faster IT GmbH | imprint | privacy policy