cbcvebase.
CVE-2024-27025
published 2024-05-01

CVE-2024-27025: In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sites within the same source code.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 44214d744be32a4769faebba764510888f1eb19e44214d744be32a4769faebba764510888f1eb19e
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 4af837db0fd3679fabc7b7758397090b0c06dced4af837db0fd3679fabc7b7758397090b0c06dced
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 98e60b538e66c90b9a856828c71d4e975ebfa79798e60b538e66c90b9a856828c71d4e975ebfa797
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 96436365e5d80d0106ea785a4f80a58e7c9edff896436365e5d80d0106ea785a4f80a58e7c9edff8
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < b7f5aed55829f376e4f7e5ea5b80ccdcb023e983b7f5aed55829f376e4f7e5ea5b80ccdcb023e983
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < e803040b368d046434fbc8a91945c690332c4fcfe803040b368d046434fbc8a91945c690332c4fcf
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < ba6a9970ce9e284cbc04099361c58731e308596aba6a9970ce9e284cbc04099361c58731e308596a
linuxlinux>= 47d902b90a32a42a3d33aef3a02170fc6f70aa23 < 31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 4.12 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.