In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftsocket: remove WARNON_ONCE on maximum cgroup level
cgroup maximum depth is INTMAX by default, there is a cgroup toggle to restrict this maximum depth to a more reasonable value not to harm performance. Remove unnecessary WARNON_ONCE which is reachable from userspace.
[ { "signature_type": "Line", "id": "CVE-2024-56783-1eb9c799", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f9bec0a749eb646b384fde0c7b7c24687b2ffae", "signature_version": "v1", "target": { "file": "net/netfilter/nft_socket.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "277995267048194650274357492054325753012", "63463391989651107398185741680871668645", "13518402046342402115694482326528468134", "107395221812232309236266932322331908445" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2024-56783-251e472b", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e227c042580ab065edc610c9ddc9bea691e6fc4d", "signature_version": "v1", "target": { "function": "nft_socket_cgroup_subtree_level", "file": "net/netfilter/nft_socket.c" }, "digest": { "function_hash": "280271610993246954191869079037379489242", "length": 275.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2024-56783-6583ca65", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e227c042580ab065edc610c9ddc9bea691e6fc4d", "signature_version": "v1", "target": { "file": "net/netfilter/nft_socket.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "277995267048194650274357492054325753012", "63463391989651107398185741680871668645", "13518402046342402115694482326528468134", "107395221812232309236266932322331908445" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2024-56783-71204359", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f9bec0a749eb646b384fde0c7b7c24687b2ffae", "signature_version": "v1", "target": { "function": "nft_socket_cgroup_subtree_level", "file": "net/netfilter/nft_socket.c" }, "digest": { "function_hash": "280271610993246954191869079037379489242", "length": 275.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2024-56783-a38a225c", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7529880cb961d515642ce63f9d7570869bbbdc3", "signature_version": "v1", "target": { "file": "net/netfilter/nft_socket.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "277995267048194650274357492054325753012", "63463391989651107398185741680871668645", "13518402046342402115694482326528468134", "107395221812232309236266932322331908445" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2024-56783-a7a18b4c", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7529880cb961d515642ce63f9d7570869bbbdc3", "signature_version": "v1", "target": { "function": "nft_socket_cgroup_subtree_level", "file": "net/netfilter/nft_socket.c" }, "digest": { "function_hash": "280271610993246954191869079037379489242", "length": 275.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2024-56783-cc47c4ab", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7064a6daa4a700a298fe3aee11dea296bfe59fc4", "signature_version": "v1", "target": { "function": "nft_socket_cgroup_subtree_level", "file": "net/netfilter/nft_socket.c" }, "digest": { "function_hash": "280271610993246954191869079037379489242", "length": 275.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2024-56783-fa044063", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7064a6daa4a700a298fe3aee11dea296bfe59fc4", "signature_version": "v1", "target": { "file": "net/netfilter/nft_socket.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "277995267048194650274357492054325753012", "63463391989651107398185741680871668645", "13518402046342402115694482326528468134", "107395221812232309236266932322331908445" ] }, "deprecated": false } ]