cbcvebase.
CVE-2024-27019
published 2024-05-01

CVE-2024-27019: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() nft_unregister_obj()…

PriorityP419medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.20%
9.7th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() nft_unregister_obj() can concurrent with __nft_obj_type_get(), and there is not any protection when iterate over nf_tables_objects list in __nft_obj_type_get(). Therefore, there is potential data-race of nf_tables_objects list entry. Use list_for_each_entry_rcu() to iterate over nf_tables_objects list in __nft_obj_type_get(), and use rcu_read_lock() in the caller nft_obj_type_get() to protect the entire type query process.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxlinux
linuxlinux>= e50092404c1bc7aaeb0a0f4077fa6f07b073a20f < cade34279c2249eafe528564bd2e203e4ff15f88cade34279c2249eafe528564bd2e203e4ff15f88
linuxlinux>= e50092404c1bc7aaeb0a0f4077fa6f07b073a20f < 379bf7257bc5f2a1b1ca8514e08a871b7bf6d920379bf7257bc5f2a1b1ca8514e08a871b7bf6d920
linuxlinux>= e50092404c1bc7aaeb0a0f4077fa6f07b073a20f < df7c0fb8c2b9f9cac65659332581b19682a71349df7c0fb8c2b9f9cac65659332581b19682a71349
linuxlinux>= e50092404c1bc7aaeb0a0f4077fa6f07b073a20f < ad333578f736d56920e090d7db1f8dec891d815ead333578f736d56920e090d7db1f8dec891d815e
linuxlinux>= e50092404c1bc7aaeb0a0f4077fa6f07b073a20f < 4ca946b19caf655a08d5e2266d4d5526025ebb734ca946b19caf655a08d5e2266d4d5526025ebb73
linuxlinux>= e50092404c1bc7aaeb0a0f4077fa6f07b073a20f < d78d867dcea69c328db30df665be5be7d0148484d78d867dcea69c328db30df665be5be7d0148484
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 4.10 < 5.15.1575.15.157
linuxlinux_kernel>= 5.16 < 6.1.886.1.88
linuxlinux_kernel>= 6.2 < 6.6.296.6.29

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.