In the Linux kernel, the following vulnerability has been resolved:
net/tcpao: Don't leak aoinfo on error-path
It seems I introduced it together with TCPAOCMDFAOREQUIRED, on version 5 [1] of TCP-AO patches. Quite frustrative that having all these selftests that I've written, running kmemtest & kcov was always in todo.
[
{
"signature_type": "Function",
"digest": {
"length": 1827.0,
"function_hash": "17326307276307647020650159480252568671"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f9ae848904289ddb16c7c9e4553ed4c64300de49",
"deprecated": false,
"id": "CVE-2024-40985-3b691e40",
"signature_version": "v1",
"target": {
"function": "tcp_ao_info_cmd",
"file": "net/ipv4/tcp_ao.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"326122390044944267053078275513831530552",
"23176509151816362148194100318323662995",
"20693375200140002911186224367022494726",
"70661759670838205266232958491603220395",
"330302003278583305857069493548668864637"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ebaa7d3c26332330a48f9a15f8e518d526cc0f21",
"deprecated": false,
"id": "CVE-2024-40985-53161720",
"signature_version": "v1",
"target": {
"file": "net/ipv4/tcp_ao.c"
}
},
{
"signature_type": "Function",
"digest": {
"length": 1827.0,
"function_hash": "17326307276307647020650159480252568671"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ebaa7d3c26332330a48f9a15f8e518d526cc0f21",
"deprecated": false,
"id": "CVE-2024-40985-68fc5373",
"signature_version": "v1",
"target": {
"function": "tcp_ao_info_cmd",
"file": "net/ipv4/tcp_ao.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"326122390044944267053078275513831530552",
"23176509151816362148194100318323662995",
"20693375200140002911186224367022494726",
"70661759670838205266232958491603220395",
"330302003278583305857069493548668864637"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f9ae848904289ddb16c7c9e4553ed4c64300de49",
"deprecated": false,
"id": "CVE-2024-40985-a2af5d44",
"signature_version": "v1",
"target": {
"file": "net/ipv4/tcp_ao.c"
}
}
]