Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 5.15, < 5.15.1
A vulnerability in the Linux kernel's handling of XFRM_MSG_MIGRATE notifications has been identified. The issue arises because the migration notifications are hardcoded to the initial network namespace, rather than the namespace of the caller. This flaw affects the IKEv2 protocol's MOBIKE and address-update handling, particularly for daemons running in non-initial network namespaces.
The vulnerability disrupts the IKEv2 MOBIKE and address-update handling within a network namespace, causing migration notifications to be misrouted or not received at all.
To reproduce this vulnerability, an IKE daemon must be run in a non-initial network namespace and subscribed to its own XFRMNLGRP_MIGRATE or pfkey groups. The daemon will not receive notifications of its own migration, leading to a broken address-update handling.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.