Description of problem: A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.
The PR Link: https://gitee.com/anolis/cloud-kernel/pulls/1998
*** Bug 6003 has been marked as a duplicate of this bug. ***
这个 CVE 应该还没有合入,不知道为何被标记为 dup 了,麻烦请再确认下
Already fixed in https://gitee.com/anolis/cloud-kernel/pulls/2335/commits. *** This bug has been marked as a duplicate of bug 7043 ***