In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: incorrect pppoe tuple
pppoe traffic reaching ingress path does not match the flowtable entry because the pppoe header is expected to be at the network header offset. This bug causes a mismatch in the flow table lookup, so pppoe packets enter the classical forwarding path.
[
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"178478939155120270176188719521706803356",
"110510760692581791348081110327564340228",
"261884585166339292957569852874152280843",
"203479715199276297927773374948227537621"
]
},
"id": "CVE-2024-27015-491e9e1f",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6db5dc7b351b9569940cd1cf445e237c42cd6d27",
"target": {
"file": "net/netfilter/nf_flow_table_ip.c"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"178478939155120270176188719521706803356",
"110510760692581791348081110327564340228",
"261884585166339292957569852874152280843",
"203479715199276297927773374948227537621"
]
},
"id": "CVE-2024-27015-6aefd877",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e719b52d0c56989b0f3475a03a6d64f182c85b56",
"target": {
"file": "net/netfilter/nf_flow_table_ip.c"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"178478939155120270176188719521706803356",
"110510760692581791348081110327564340228",
"261884585166339292957569852874152280843",
"203479715199276297927773374948227537621"
]
},
"id": "CVE-2024-27015-c5cc2f77",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f1c3c61701a0b12f4906152c1626a5de580ea3d2",
"target": {
"file": "net/netfilter/nf_flow_table_ip.c"
}
}
]