netfilter: x_tables: fix compat match/target pad out-of-bound write
Bug #1927682 reported by
Khaled El Mously
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Incomplete
|
Undecided
|
Unassigned | ||
Focal |
Fix Released
|
Medium
|
Unassigned | ||
Groovy |
Fix Released
|
Medium
|
Unassigned | ||
Hirsute |
Invalid
|
Medium
|
Unassigned | ||
linux-5.4 (Ubuntu) |
New
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
This issue:
https:/
[Impact]
Data corruption and/or leak.
[Fix]
Zero out entire data structure beforehand
[Test]
Boot-test only so far.
[Regression Potential]
Possible effect on iptables/nftables. Though considered minimal risk as the patch has only a very localized effect and is accepted upstream in v5.12
description: | updated |
no longer affects: | kernel-sru-workflow |
Changed in linux (Ubuntu Hirsute): | |
importance: | Undecided → Medium |
status: | Incomplete → In Progress |
Changed in linux (Ubuntu Groovy): | |
importance: | Undecided → Medium |
status: | Incomplete → In Progress |
Changed in linux (Ubuntu Focal): | |
importance: | Undecided → Medium |
status: | Incomplete → In Progress |
Changed in linux (Ubuntu Bionic): | |
importance: | Undecided → Medium |
status: | Incomplete → In Progress |
Changed in linux (Ubuntu Hirsute): | |
status: | In Progress → Invalid |
Changed in linux (Ubuntu Groovy): | |
status: | In Progress → Fix Committed |
Changed in linux (Ubuntu Bionic): | |
status: | In Progress → Fix Committed |
Changed in linux (Ubuntu Focal): | |
status: | In Progress → Fix Committed |
no longer affects: | linux-5.4 (Ubuntu Focal) |
no longer affects: | linux-5.4 (Ubuntu Groovy) |
no longer affects: | linux-5.4 (Ubuntu Hirsute) |
Changed in linux-5.4 (Ubuntu Bionic): | |
status: | New → Fix Released |
no longer affects: | linux (Ubuntu Bionic) |
Changed in linux (Ubuntu Focal): | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:
apport-collect 1927682
and then change the status of the bug to 'Confirmed'.
If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.
This change has been made by an automated script, maintained by the Ubuntu Kernel Team.