In the Linux kernel, the following vulnerability has been resolved: ipvs: do not keep dest_dst if dev is going down There is race between the netdev notifier ip_vs_dst_event() and the code that caches dst with dev that is going down. As the FIB can be notified for the closed device after our handler finishes, it is possible valid route to be returned and cached resuling in a leaked dev reference until the dest is not removed. To prevent new dest_dst to be attached to dest just after the handler dropped the old one, add a netif_running() check to make sure the notifier handler is not currently running for device that is closing.
Update Linux/Linux to 64af43033503458c46023e56d6ae7bb0f824b55f if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanipvs: do not keep dest_dst if dev is going down affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: ipvs: do not keep dest_dst if dev is going down There is race between the netdev notifier ip_vs_dst_event() and the code that caches dst with dev that is going down. As the FIB can be notified for the closed device after our handler finishes, it is possible valid route to be returned and cached resuling in a leaked dev reference until the dest is not removed. To prevent new dest_dst to be attached to dest just after the handler dropped the old one, add a netif_running() check to make sure the notifier handler is not currently running for device that is closing.
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linux |
In the Linux kernel, the following vulnerability has been resolved: ipvs: do not keep dest_dst if dev is going down There is race between the netdev notifier ip_vs_dst_event() and the code that caches dst with dev that is going down. As the FIB can be notified for the closed device after our handler finishes, it is possible valid route to be returned and cached resuling in a leaked dev reference until the dest is not removed. To prevent new dest_dst to be attached to dest just after the handler dropped the old one, add a netif_running() check to make sure the notifier handler is not currently running for device that is closing.
Update Linux/Linux to 64af43033503458c46023e56d6ae7bb0f824b55f if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanipvs: do not keep dest_dst if dev is going down affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: ipvs: do not keep dest_dst if dev is going down There is race between the netdev notifier ip_vs_dst_event() and the code that caches dst with dev that is going down. As the FIB can be notified for the closed device after our handler finishes, it is possible valid route to be returned and cached resuling in a leaked dev reference until the dest is not removed. To prevent new dest_dst to be attached to dest just after the handler dropped the old one, add a netif_running() check to make sure the notifier handler is not currently running for device that is closing.
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linux |
| >=7a4f0761fce32ff4918a7c23b08db564ad33092d <64af43033503458c46023e56d6ae7bb0f824b55f || >=7a4f0761fce32ff4918a7c23b08db564ad33092d <bae53b3baf2ff2f45f9205c438818fc055601a54 || >=7a4f0761fce32ff4918a7c23b08db564ad33092d <024eb0bd19f507e6e7f0c7a7e5506d66b5dc1d3e || >=7a4f0761fce32ff4918a7c23b08db564ad33092d <8fde939b0206afc1d5846217a01a16b9bc8c7896 |
| 64af43033503458c46023e56d6ae7bb0f824b55f, bae53b3baf2ff2f45f9205c438818fc055601a54, 024eb0bd19f507e6e7f0c7a7e5506d66b5dc1d3e, 8fde939b0206afc1d5846217a01a16b9bc8c7896 |
| Linux/Linuxgeneric | 2.6.39 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=7a4f0761fce32ff4918a7c23b08db564ad33092d <64af43033503458c46023e56d6ae7bb0f824b55f || >=7a4f0761fce32ff4918a7c23b08db564ad33092d <bae53b3baf2ff2f45f9205c438818fc055601a54 || >=7a4f0761fce32ff4918a7c23b08db564ad33092d <024eb0bd19f507e6e7f0c7a7e5506d66b5dc1d3e || >=7a4f0761fce32ff4918a7c23b08db564ad33092d <8fde939b0206afc1d5846217a01a16b9bc8c7896 |
| 64af43033503458c46023e56d6ae7bb0f824b55f, bae53b3baf2ff2f45f9205c438818fc055601a54, 024eb0bd19f507e6e7f0c7a7e5506d66b5dc1d3e, 8fde939b0206afc1d5846217a01a16b9bc8c7896 |
| Linux/Linuxgeneric | 2.6.39 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard