A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The improper cleanup results in out-of-boundary read, where a local user can utilize this problem to crash the system or escalation of privilege.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.spinics.net/lists/linux-rdma/msg114749.html | patch mailing list third party advisory |
https://security.netapp.com/advisory/ntap-20230609-0005/ | third party advisory |