An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
| Software | From | Fixed in |
|---|---|---|
| redhat / enterprise_linux | 8.0 | 8.0.x |
| redhat / enterprise_linux | 9.0 | 9.0.x |
| linux / linux_kernel | 5.5 | 5.10.154 |
| linux / linux_kernel | 5.11 | 5.15.78 |
| linux / linux_kernel | 5.16 | 6.0.8 |
| linux / linux_kernel | 4.20 | 5.4.224 |
| linux / linux_kernel | 4.15 | 4.19.265 |