CVE-2024-27016 — Linux vulnerability
20 documents9 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: validate pppoe header
Ensure there is sufficient room to access the protocol field of the
PPPoe header. Validate it once before the flowtable lookup, then use a
helper function to access protocol field.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages3 packages
▶CVEListV5linux/linux72efd585f7144a047f7da63864284764596ccad9 — d06977b9a4109f8738bb276125eb6a0b772bc433+5
Also affects: Fedora 38, 39, 40
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-gjj3-fh9w-h2f7: In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: validate pppoe header
Ensure there is sufficient room to a↗2024-05-01
OSV▶
CVE-2024-27016: In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate pppoe header Ensure there is sufficient room to acc↗2024-05-01