netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()
nf_osf_find() incorrectly returns true on mismatch, this leads to
copying uninitialized memory area in nft_osf which can be used to leak
stale kernel stack data to userspace.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 30 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2026-08-04T09:01:53.101Z
Reserved: 2024-02-25T13:44:28.317Z
Link: CVE-2022-48654
Updated: 2024-08-03T15:17:55.613Z
Status : Modified
Published: 2024-04-28T13:15:07.580
Modified: 2026-06-17T05:15:50.073
Link: CVE-2022-48654
OpenCVE Enrichment
No data.
-
CWE-908
Use of Uninitialized Resource