In the Linux kernel, the following vulnerability has been...
High severity
Unreviewed
Published
Jun 20, 2024
to the GitHub Advisory Database
•
Updated Sep 17, 2025
Description
Published by the National Vulnerability Database
Jun 20, 2024
Published to the GitHub Advisory Database
Jun 20, 2024
Last updated
Sep 17, 2025
In the Linux kernel, the following vulnerability has been resolved:
net: fix information leakage in /proc/net/ptype
In one net namespace, after creating a packet socket without binding
it to a device, users in other net namespaces can observe the new
packet_typeadded by this packet socket by reading/proc/net/ptypefile. This is minor information leakage as packet socket is
namespace aware.
Add a net pointer in
packet_typeto keep the net namespace ofof corresponding packet socket. In
ptype_seq_show, this net pointermust be checked when it is not NULL.
References