The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 24861ef8b517a309a4225f2793be0cd8fa0bec9e |