In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent possible UAF in ip6_xmit()
If skbexpandhead() returns NULL, skb has been freed and the associated dst/idev could also have been freed.
We must use rcureadlock() to prevent a possible UAF.
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2374.0,
"function_hash": "257904842902109325044011356100616684719"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2d5ff7e339d04622d8282661df36151906d0e1c7",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "ip6_xmit"
},
"id": "CVE-2024-44985-060f6481"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"53458417411036856138282181531635571419",
"7891445641594684130530665419644758138",
"69890119548043594470274969445948151737",
"176531933359355517637259134920000171582",
"289145317399674226154485350328782261494",
"15253652675921018726110052793828364225",
"234417572947199921494995913766542411272",
"6808485886626584458785948596939744221",
"267546462884765554161030880927979632545"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@975f764e96f71616b530e300c1bb2ac0ce0c2596",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"id": "CVE-2024-44985-522ae8e0"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"53458417411036856138282181531635571419",
"7891445641594684130530665419644758138",
"69890119548043594470274969445948151737",
"176531933359355517637259134920000171582",
"289145317399674226154485350328782261494",
"15253652675921018726110052793828364225",
"234417572947199921494995913766542411272",
"6808485886626584458785948596939744221",
"267546462884765554161030880927979632545"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b3a3d5333c13a1be57499581eab4a8fc94d57f36",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"id": "CVE-2024-44985-52cd82f5"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"235586764519184076403144563939626175586",
"7891445641594684130530665419644758138",
"69890119548043594470274969445948151737",
"176531933359355517637259134920000171582",
"289145317399674226154485350328782261494",
"15253652675921018726110052793828364225",
"234417572947199921494995913766542411272",
"6808485886626584458785948596939744221",
"267546462884765554161030880927979632545"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@38a21c026ed2cc7232414cb166efc1923f34af17",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"id": "CVE-2024-44985-59a2baea"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2004.0,
"function_hash": "13213428196257317996138500698640222955"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b3a3d5333c13a1be57499581eab4a8fc94d57f36",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "ip6_xmit"
},
"id": "CVE-2024-44985-9e867f5b"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"235586764519184076403144563939626175586",
"7891445641594684130530665419644758138",
"69890119548043594470274969445948151737",
"176531933359355517637259134920000171582",
"289145317399674226154485350328782261494",
"15253652675921018726110052793828364225",
"234417572947199921494995913766542411272",
"6808485886626584458785948596939744221",
"267546462884765554161030880927979632545"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2d5ff7e339d04622d8282661df36151906d0e1c7",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"id": "CVE-2024-44985-a7c282f9"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2366.0,
"function_hash": "326685757192526129828774099941572266977"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@38a21c026ed2cc7232414cb166efc1923f34af17",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "ip6_xmit"
},
"id": "CVE-2024-44985-acba8f93"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2004.0,
"function_hash": "13213428196257317996138500698640222955"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c47e022011719fc5727bca661d662303180535ba",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "ip6_xmit"
},
"id": "CVE-2024-44985-c96a9d1b"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"53458417411036856138282181531635571419",
"7891445641594684130530665419644758138",
"69890119548043594470274969445948151737",
"176531933359355517637259134920000171582",
"289145317399674226154485350328782261494",
"15253652675921018726110052793828364225",
"234417572947199921494995913766542411272",
"6808485886626584458785948596939744221",
"267546462884765554161030880927979632545"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c47e022011719fc5727bca661d662303180535ba",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"id": "CVE-2024-44985-cecf58eb"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2004.0,
"function_hash": "13213428196257317996138500698640222955"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@975f764e96f71616b530e300c1bb2ac0ce0c2596",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "ip6_xmit"
},
"id": "CVE-2024-44985-f97c53ad"
}
]