Description: net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free References: https://kernel.dance/b80b829e9e2c1b3f7aae34855e04d8f6ecaf13c8 Notes: carnil> CVE-2023-4206 is from Google CNA a subset of CVE-2023-4128 carnil> assigned by RedHat CNA. carnil> For 6.4.y fixed in 6.4.10. Bugs: upstream: released (6.5-rc5) [b80b829e9e2c1b3f7aae34855e04d8f6ecaf13c8] 6.1-upstream-stable: released (6.1.45) [d4d3b53a4c66004e8e864fea744b3a2b86a73b62] 5.10-upstream-stable: released (5.10.190) [aaa71c4e8ad98828ed50dde3eec8e0d545a117f7] 4.19-upstream-stable: released (4.19.291) [ad8f36f96696a7f1d191da66637c415959bab6d8] sid: released (6.4.11-1) 6.1-bookworm-security: released (6.1.52-1) 5.10-bullseye-security: released (5.10.191-1) 4.19-buster-security: released (4.19.304-1)