OSV 1.4.0 · unreviewed · 修改于 2026-09-04 14:31
发布时间
2026-09-03 23:32
GitHub 审查时间
—
NVD 发布时间
2026-09-03 21:06
源文件
advisories/unreviewed/2026/09/GHSA-2h35-47m3-h9hp/GHSA-2h35-47m3-h9hp.json
In the Linux kernel, the following vulnerability has been resolved:
ovpn: ensure socket is owned by ovpn before deref sk_user_data
Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type.
For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data.
Failing to do so may lead to out-of-bounds reads.
该公告没有提供结构化的受影响软件包信息。