Back

LOW

kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied

Published Mar 24, 2014

Description

Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 24, 2014
Updated Aug 6, 2024
Reserved Mar 20, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 18, 2014