Bug 1227375 (CVE-2024-6284) - VUL-0: TRACKERBUG: CVE-2024-6284: google/nftables: incorrect IP address encoded bytes may lead to unwanted behavior
Summary: VUL-0: TRACKERBUG: CVE-2024-6284: google/nftables: incorrect IP address encod...
Status: NEW
Alias: CVE-2024-6284
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/412835/
Whiteboard:
Keywords:
Depends on: 1227376
Blocks:
  Show dependency treegraph
 
Reported: 2024-07-04 08:05 UTC by SMASH SMASH
Modified: 2024-07-04 08:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Thomas Leroy 2024-07-04 08:06:50 UTC
github.com/google/nftables Go module is embedded in:

- openSUSE:Factory/talosctl (already fixed)
- openSUSE:Factory/tailscale
Comment 2 Thomas Leroy 2024-07-04 08:09:06 UTC
According to [0] the issue was introduced in [1] (1.0.0)

[0] https://github.com/google/nftables/issues/225#issuecomment-1549973369
[1] https://github.com/google/nftables/pull/180