CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's netfilter component, specifically in the u32_match_it() function, where malformed u32 rules can lead to an out-of-bounds shift operation during packet evaluation. This could potentially allow an attacker to exploit the vulnerability to cause denial of service or other unintended behavior in network traffic processing. System administrators and security teams managing Linux-based systems should prioritize addressing this issue to ensure the integrity and stability of their network environments.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_u32: reject invalid shift counts u32_match_it() executes rule-supplied shift operands on a 32-bit value. A malformed u32 rule can provide a shift count of 32 or more, triggering an undefined shift out-of-bounds during packet evaluation. Validate XT_U32_LEFTSH and XT_U32_RIGHTSH operands in u32_mt_checkentry() and reject malformed rules before they reach the packet path.