In the Linux kernel, the following vulnerability has been...
High severity
Unreviewed
Published
Jun 20, 2024
to the GitHub Advisory Database
•
Updated Sep 17, 2025
Description
Published by the National Vulnerability Database
Jun 20, 2024
Published to the GitHub Advisory Database
Jun 20, 2024
Last updated
Sep 17, 2025
In the Linux kernel, the following vulnerability has been resolved:
net: fix information leakage in /proc/net/ptype
In one net namespace, after creating a packet socket without binding
it to a device, users in other net namespaces can observe the new
packet_type
added by this packet socket by reading/proc/net/ptype
file. This is minor information leakage as packet socket is
namespace aware.
Add a net pointer in
packet_type
to keep the net namespace ofof corresponding packet socket. In
ptype_seq_show
, this net pointermust be checked when it is not NULL.
References