CVE-2024-35896
Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel
In the Linux kernel, the following vulnerability has been resolved: netfilter: validate user input for expected length I got multiple syzbot reports showing old bugs exposed by BPF after commit 20f2505fb436 ("bpf: Try to avoid kzalloc in cgroup/{s,g}etsockopt") setsockopt() @optlen argument should be taken into account before copying data. BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in do_replace net/ipv4/netfilter/ip_table...
- CVSS
- 7.1
- EPSS
- 0.23% 13.4% percentile
- CISA KEV
- Not listed
- Published
- 2024.05.19