Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Product status
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before 59e656d0d4a84ea0ee9a39c6f69160a3effccc94
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before 04bf69e3de435d793a203aacc4b774f8f9f2baeb
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before 011f47c8b8389154f996f5f69da8efc3a3beefef
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before e5f82688ae10f5f386952e65e941bb8868ee54dc
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before 9b92e2d0eb696d7586ba832c8854653b59887da0
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before 91dd8aab9c9f193210681b86b6b92840ffe74f0c
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before ae68c0f7edbc9a294094ce03a0aaf45aa489ce40
c61a404325093250b676f40ad8f4dd00f3bcab5f (git) before 878ecb0897f4737a4c9401f3523fd49589025671
2.6.19
Any version before 2.6.19
4.14.316 (semver)
4.19.284 (semver)
5.4.244 (semver)
5.10.181 (semver)
5.15.114 (semver)
6.1.31 (semver)
6.3.5 (semver)
6.4 (original_commit_for_fix)
References
git.kernel.org/...c/59e656d0d4a84ea0ee9a39c6f69160a3effccc94
git.kernel.org/...c/04bf69e3de435d793a203aacc4b774f8f9f2baeb
git.kernel.org/...c/011f47c8b8389154f996f5f69da8efc3a3beefef
git.kernel.org/...c/e5f82688ae10f5f386952e65e941bb8868ee54dc
git.kernel.org/...c/9b92e2d0eb696d7586ba832c8854653b59887da0
git.kernel.org/...c/91dd8aab9c9f193210681b86b6b92840ffe74f0c
git.kernel.org/...c/ae68c0f7edbc9a294094ce03a0aaf45aa489ce40
git.kernel.org/...c/878ecb0897f4737a4c9401f3523fd49589025671