In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calculate expect ID Delete expectation path is missing a call to the nf_expect_get_id() helper function to calculate the expectation ID, otherwise LSB of the expectation object address is leaked to userspace.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024083044-CVE-2024-44944-56c0@gregkh/T