In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftsocket: remove WARNON_ONCE on maximum cgroup level
cgroup maximum depth is INTMAX by default, there is a cgroup toggle to restrict this maximum depth to a more reasonable value not to harm performance. Remove unnecessary WARNON_ONCE which is reachable from userspace.
[
{
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f9bec0a749eb646b384fde0c7b7c24687b2ffae",
"deprecated": false,
"id": "CVE-2024-56783-1eb9c799",
"target": {
"file": "net/netfilter/nft_socket.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"277995267048194650274357492054325753012",
"63463391989651107398185741680871668645",
"13518402046342402115694482326528468134",
"107395221812232309236266932322331908445"
]
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f9bec0a749eb646b384fde0c7b7c24687b2ffae",
"deprecated": false,
"id": "CVE-2024-56783-71204359",
"target": {
"function": "nft_socket_cgroup_subtree_level",
"file": "net/netfilter/nft_socket.c"
},
"digest": {
"function_hash": "280271610993246954191869079037379489242",
"length": 275.0
},
"signature_type": "Function"
}
]