3 ms·
> ## Patch > Since the vulnerable operation in nft_payload_copy_vlan should account for the encapsulated VLAN tag, I suspect that the last plus sign should hav
by 2bluesc 4y ago
> ## Patch
> Since the vulnerable operation in nft_payload_copy_vlan should account for the encapsulated VLAN tag, I suspect that the last plus sign should have been a minus since it prevents any wrapping.
> ## Mitigating the bug
> If you are unable to patch this bug, disabling unprivileged user namespaces will prevent exploitation:
sysctl -w kernel.unprivileged_userns_clone = 0