A bridge firewall rule feature in ebtables’ SNAT target can be tricked into writing an ARP address rewrite straight into unprepared kernel memory, corrupting it.
Posts tagged: Linux
Linux Kernel Race Condition Vulnerability
A local, low-privileged process can race concurrent writes to the same AF_ALG crypto socket, corrupting kernel state with confidentiality, integrity and availability impact.