cbcvebase.
CVE-2024-27015
published 2024-05-01

CVE-2024-27015: In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not match the flowtable entry because the pppoe header is expected to be at the network header offset. This bug causes a mismatch in the flow table lookup, so pppoe packets enter the classical forwarding path.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxlinux
linuxlinux>= 72efd585f7144a047f7da63864284764596ccad9 < e719b52d0c56989b0f3475a03a6d64f182c85b56e719b52d0c56989b0f3475a03a6d64f182c85b56
linuxlinux>= 72efd585f7144a047f7da63864284764596ccad9 < f1c3c61701a0b12f4906152c1626a5de580ea3d2f1c3c61701a0b12f4906152c1626a5de580ea3d2
linuxlinux>= 72efd585f7144a047f7da63864284764596ccad9 < 4ed82dd368ad883dc4284292937b882f044e625d4ed82dd368ad883dc4284292937b882f044e625d
linuxlinux>= 72efd585f7144a047f7da63864284764596ccad9 < e3f078103421642fcd5f05c5e70777feb10f000de3f078103421642fcd5f05c5e70777feb10f000d
linuxlinux>= 72efd585f7144a047f7da63864284764596ccad9 < 6db5dc7b351b9569940cd1cf445e237c42cd6d276db5dc7b351b9569940cd1cf445e237c42cd6d27
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 5.13 < 5.15.1575.15.157
linuxlinux_kernel>= 5.16 < 6.1.886.1.88
linuxlinux_kernel>= 6.2 < 6.6.296.6.29
linuxlinux_kernel>= 6.7 < 6.8.86.8.8
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.8MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.