Shocking! A 16-Year-Old Vulnerability Lurking in the Linux Kernel
CVE-2021-42008 is a Slab-Out-Of-Bounds Write vulnerability in the Linux 6pack driver, caused by a lack of size validation checks in the decode_data function. Malicious input from a process with CAP_NET_ADMIN capabilities may lead to an overflow of the Cooked_buf field in the Sixpack structure, resulting in kernel memory corruption. If exploited correctly, this could lead … Read more