Comment 1 for bug 2059991

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux - 6.5.0-42.42

---------------
linux (6.5.0-42.42) mantic; urgency=medium

  * mantic/linux: 6.5.0-42.42 -proposed tracker (LP: #2068188)

  * CVE-2024-26925
    - netfilter: nf_tables: release batch on table validation from abort path
    - netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path

  * CVE-2024-26924
    - netfilter: nft_set_pipapo: do not free live element

  * CVE-2024-26809
    - netfilter: nft_set_pipapo: release elements in clone only from destroy path

  * Mantic update: upstream stable patchset 2024-04-02 (LP: #2059991) //
    CVE-2024-26809
    - netfilter: nft_set_pipapo: store index in scratch maps
    - netfilter: nft_set_pipapo: add helper to release pcpu scratch area
    - netfilter: nft_set_pipapo: remove scratch_aligned pointer

  * CVE-2024-26643
    - netfilter: nf_tables: mark set as dead when unbinding anonymous set with
      timeout

 -- Roxana Nicolescu <email address hidden> Mon, 10 Jun 2024 10:19:54 +0200