BPF cgroup link update fixed for stack out-of-bounds write
Replacement programs were matched only by type, so incompatible sock_addr and LSM hooks could clobber adjacent stack state.
By kexecReplacement programs were matched only by type, so incompatible sock_addr and LSM hooks could clobber adjacent stack state.
By kexecAuthenticated clients could force undersized ACL headers or heap out-of-bounds reads via crafted security descriptors.
By oops