CVE-2024-50038

netfilter: xtables: avoid NFPROTO_UNSPEC where needed

References

Notes

 carnil> Introduced in 0269ea493734 ("netfilter: xtables: add cluster match").
 carnil> Vulnerable versions: 2.6.30-rc1.

Bugs

Status

Branch Status
upstream released (6.12-rc3) [0bfcb7b71e735560077a42847f69597ec7dcc326]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.11-upstream-stable released (6.11.4) [4cdc55ec6222bb195995cc58f7cb46e4d8907056]
6.6-upstream-stable released (6.6.57) [997f67d813ce0cf5eb3cdb8f124da68141e91b6c]
6.1-upstream-stable released (6.1.113) [8f482bb7e27b37f1f734bb9a8eeb28b23d59d189]
5.10-upstream-stable needed
sid released (6.11.4-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.115-1)
5.10-bullseye-security needed