In the Linux kernel, the following vulnerability has been resolved:net/sched: act_mirred: don't override retval if we already lost the skbIf we're redirecting the skb, and haven't called tcf_mirred_forward(),yet, we need to tell the core to drop the skb by setting the retcodeto SHOT. If we have called tcf_mirred_forward(), however, the skbis out of our hands and returning SHOT will lead to UaF.Move the retval override to the error path which actually need it.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/bygregonline/devsec-fastapi-report
- https://github.com/runwhen-contrib/helm-charts
- https://github.com/w4zu/Debian_security