In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftsocket: remove WARNON_ONCE on maximum cgroup level
cgroup maximum depth is INTMAX by default, there is a cgroup toggle to restrict this maximum depth to a more reasonable value not to harm performance. Remove unnecessary WARNON_ONCE which is reachable from userspace.
[
{
"target": {
"function": "nft_socket_cgroup_subtree_level",
"file": "net/netfilter/nft_socket.c"
},
"digest": {
"length": 275.0,
"function_hash": "280271610993246954191869079037379489242"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e227c042580ab065edc610c9ddc9bea691e6fc4d",
"deprecated": false,
"id": "CVE-2024-56783-251e472b",
"signature_type": "Function"
},
{
"target": {
"file": "net/netfilter/nft_socket.c"
},
"digest": {
"line_hashes": [
"277995267048194650274357492054325753012",
"63463391989651107398185741680871668645",
"13518402046342402115694482326528468134",
"107395221812232309236266932322331908445"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e227c042580ab065edc610c9ddc9bea691e6fc4d",
"deprecated": false,
"id": "CVE-2024-56783-6583ca65",
"signature_type": "Line"
},
{
"target": {
"file": "net/netfilter/nft_socket.c"
},
"digest": {
"line_hashes": [
"277995267048194650274357492054325753012",
"63463391989651107398185741680871668645",
"13518402046342402115694482326528468134",
"107395221812232309236266932322331908445"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7529880cb961d515642ce63f9d7570869bbbdc3",
"deprecated": false,
"id": "CVE-2024-56783-a38a225c",
"signature_type": "Line"
},
{
"target": {
"function": "nft_socket_cgroup_subtree_level",
"file": "net/netfilter/nft_socket.c"
},
"digest": {
"length": 275.0,
"function_hash": "280271610993246954191869079037379489242"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7529880cb961d515642ce63f9d7570869bbbdc3",
"deprecated": false,
"id": "CVE-2024-56783-a7a18b4c",
"signature_type": "Function"
}
]