Linux Kernel ChromeOS Out-of-Bounds Read Vulnerability in Netfilter/IPSet

Vulnerability

A vulnerability allowing an out-of-bounds read has been identified in the netfilter/ipset component of the Linux Kernel, specifically in ChromeOS versions 6.1, 5.15, 5.10, 5.4, and 4.19. This vulnerability allows a local attacker with low privileges to trigger the out-of-bounds read, potentially leading to information disclosure.

Impact

Exploitation of this vulnerability causes a memory corruption issue, which could be leveraged for information disclosure or to escalate privileges, particularly within the ChromeOS Termina environment.

Reproduction

The vulnerability can be reproduced by compiling a proof-of-concept C file with GCC and running the resulting executable. The proof-of-concept must be crafted to exploit the specific conditions of the vulnerability, taking advantage of the IP set commands that trigger the out-of-bounds read.

Remediation

The vulnerability has been fixed in the upstream Linux kernel and the patches have been merged. The fix will be included in the next regular sync of the ChromeOS kernel.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.6
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.