CVE-2024-27025
published 2024-05-01CVE-2024-27025: In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
nbd: null check for nla_nest_start
nla_nest_start() may fail and return NULL. Insert a check and set errno
based on other call sites within the same source code.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 6.1.85-1 (bookworm) | linux 6.1.85-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 44214d744be32a4769faebba764510888f1eb19e | 44214d744be32a4769faebba764510888f1eb19e |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 4af837db0fd3679fabc7b7758397090b0c06dced | 4af837db0fd3679fabc7b7758397090b0c06dced |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 98e60b538e66c90b9a856828c71d4e975ebfa797 | 98e60b538e66c90b9a856828c71d4e975ebfa797 |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 96436365e5d80d0106ea785a4f80a58e7c9edff8 | 96436365e5d80d0106ea785a4f80a58e7c9edff8 |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < b7f5aed55829f376e4f7e5ea5b80ccdcb023e983 | b7f5aed55829f376e4f7e5ea5b80ccdcb023e983 |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < e803040b368d046434fbc8a91945c690332c4fcf | e803040b368d046434fbc8a91945c690332c4fcf |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < ba6a9970ce9e284cbc04099361c58731e308596a | ba6a9970ce9e284cbc04099361c58731e308596a |
| linux | linux | >= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d | 31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d |
| linux | linux_kernel | >= 0 < 5.10.216-1 | 5.10.216-1 |
| linux | linux_kernel | >= 0 < 6.1.85-1 | 6.1.85-1 |
| linux | linux_kernel | >= 0 < 6.7.12-1 | 6.7.12-1 |
| linux | linux_kernel | >= 0 < 6.7.12-1 | 6.7.12-1 |
| linux | linux_kernel | >= 4.12 < 5.4.273 | 5.4.273 |
| linux | linux_kernel | >= 5.11 < 5.15.153 | 5.15.153 |
| linux | linux_kernel | >= 5.16 < 6.1.83 | 6.1.83 |
| linux | linux_kernel | >= 5.5 < 5.10.214 | 5.10.214 |
| linux | linux_kernel | >= 6.2 < 6.6.23 | 6.6.23 |
| linux | linux_kernel | >= 6.7 < 6.7.11 | 6.7.11 |
| linux | linux_kernel | >= 6.8 < 6.8.2 | 6.8.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-27025: In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL
osv·2024-05-01·CVSS 5.5
CVE-2024-27025 [MEDIUM] CVE-2024-27025: In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL
In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sites within the same source code.
GHSA
GHSA-gmgh-9qgw-5r7q: In the Linux kernel, the following vulnerability has been resolved:
nbd: null check for nla_nest_start
nla_nest_start() may fail and return NULL
ghsa_unreviewed·2024-05-01
CVE-2024-27025 [MEDIUM] CWE-476 GHSA-gmgh-9qgw-5r7q: In the Linux kernel, the following vulnerability has been resolved:
nbd: null check for nla_nest_start
nla_nest_start() may fail and return NULL
In the Linux kernel, the following vulnerability has been resolved:
nbd: null check for nla_nest_start
nla_nest_start() may fail and return NULL. Insert a check and set errno
based on other call sites within the same source code.
Red Hat
kernel: nbd: null check for nla_nest_start
vendor_redhat·2024-05-01·CVSS 5.5
CVE-2024-27025 [MEDIUM] kernel: nbd: null check for nla_nest_start
kernel: nbd: null check for nla_nest_start
In the Linux kernel, the following vulnerability has been resolved:
nbd: null check for nla_nest_start
nla_nest_start() may fail and return NULL. Insert a check and set errno
based on other call sites within the same source code.
In the Linux kernel, the following vulnerability has been resolved:
nbd: null check for nla_nest_start
The Linux kernel CVE team has assigned CVE-2024-27025 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050107-CVE-2024-27025-babd@gregkh/T
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Fix de
Debian
CVE-2024-27025: linux - In the Linux kernel, the following vulnerability has been resolved: nbd: null c...
vendor_debian·2024·CVSS 5.5
CVE-2024-27025 [MEDIUM] CVE-2024-27025: linux - In the Linux kernel, the following vulnerability has been resolved: nbd: null c...
In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sites within the same source code.
Scope: local
bookworm: resolved (fixed in 6.1.85-1)
bullseye: resolved (fixed in 5.10.216-1)
forky: resolved (fixed in 6.7.12-1)
sid: resolved (fixed in 6.7.12-1)
trixie: resolved (fixed in 6.7.12-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6dhttps://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19ehttps://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dcedhttps://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596ahttps://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcfhttps://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6dhttps://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19ehttps://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dcedhttps://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596ahttps://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcfhttps://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.html
2024-05-01
Published