CVE-2024-42070

Source
https://cve.org/CVERecord?id=CVE-2024-42070
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42070.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-42070
Downstream
Related
Published
2024-07-29T15:52:34.061Z
Modified
2026-03-23T05:00:46.608808796Z
Summary
netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nftables: fully validate NFTDATA_VALUE on store to data registers

register store validation for NFTDATAVALUE is conditional, however, the datatype is always either NFTDATAVALUE or NFTDATAVERDICT. This only requires a new helper function to infer the register type from the set datatype so this conditional check can be removed. Otherwise, pointer to chain object can be leaked through the registers.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42070.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
96518518cc417bb0a8c80b9fb736202e28acdf96
Fixed
40188a25a9847dbeb7ec67517174a835a677752f
Fixed
23752737c6a618e994f9a310ec2568881a6b49c4
Fixed
5d43d789b57943720dca4181a05f6477362b94cf
Fixed
461302e07f49687ffe7d105fa0a330c07c7646d8
Fixed
efb27ad05949403848f487823b597ed67060e007
Fixed
952bf8df222599baadbd4f838a49c4fef81d2564
Fixed
41a6375d48deaf7f730304b5153848bfa1c2980f
Fixed
7931d32955e09d0a11b1fe0b6aac1bfa061c005c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42070.json"