Block family NETLINK_KOBJECT_UEVENT of AF_NETLINK socket #37

Open
opened 2026-03-31 19:52:30 +09:00 by ophestra · 0 comments
Owner

This allows any unprivileged user to receive uevent multicasts from the kernel. These are hardware driver state changes and considered sensitive and identifying in most use cases. It additionally enables a DoS by exhausting available port IDs.

This allows any unprivileged user to receive uevent multicasts from the kernel. These are hardware driver state changes and considered sensitive and identifying in most use cases. It additionally enables a DoS by exhausting available port IDs.
ophestra added the
Kind
Security
Priority
High
Reviewed
Confirmed
labels 2026-03-31 19:52:30 +09:00
ophestra added a new dependency 2026-03-31 19:52:49 +09:00
Sign in to join this conversation.