nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.
| Software | From | Fixed in |
|---|---|---|
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |
| linux / linux_kernel | 2.6.14 | 4.9.326 |
| linux / linux_kernel | 4.10 | 4.14.291 |
| linux / linux_kernel | 4.15 | 4.19.255 |
| linux / linux_kernel | 4.20 | 5.4.209 |
| linux / linux_kernel | 5.5 | 5.10.135 |
| linux / linux_kernel | 5.11 | 5.15.59 |
| linux / linux_kernel | 5.16 | 5.18.16 |