ASB-A-197154735
Dashboard / Vulnerabilities / ASB-A-197154735
Summary:
Details: In sctp_v6_to_sk_daddr, sctp_v4_from_addr_param, and related functions of ipv6.c, protocol.c, and related files, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to an on-path attacker with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2022-03-01, https://android.googlesource.com/kernel/common/+/d4dbef7046e2, https://android.googlesource.com/kernel/common/+/6ef81a5c0e22, https://android.googlesource.com/kernel/common/+/ffca46766850, https://android.googlesource.com/kernel/common/+/ccb79116c372
Affected packages
Package
Name: :linux_kernel:
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
