cbcvebase.
CVE-2024-27390
published 2024-05-01

CVE-2024-27390: In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down() As discussed in the…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down() As discussed in the past (commit 2d3916f31891 ("ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()")) I think the synchronize_net() call in ipv6_mc_down() is not needed. Under load, synchronize_net() can last between 200 usec and 5 ms. KASAN seems to agree as well.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 94d6a071ab2f26eb18a83109940db0cec19552fd < bfd2f3c58ad86ad33db80515e6c3503e0414e44bbfd2f3c58ad86ad33db80515e6c3503e0414e44b
linuxlinux>= f185de28d9ae6c978135993769352e523ee8df06 < 9d159d6637ccce25f879d662a480541ef4ba3a509d159d6637ccce25f879d662a480541ef4ba3a50
linuxlinux>= f185de28d9ae6c978135993769352e523ee8df06 < a03ede2282ebbd181bd6f5c38cbfcb5765afcd04a03ede2282ebbd181bd6f5c38cbfcb5765afcd04
linuxlinux>= f185de28d9ae6c978135993769352e523ee8df06 < 26d4bac55750d535f1f0b8790dc26daf6089e37326d4bac55750d535f1f0b8790dc26daf6089e373
linuxlinux>= f185de28d9ae6c978135993769352e523ee8df06 < 7eb06ee5921189812e6b4bfe7b0f1e878be16df77eb06ee5921189812e6b4bfe7b0f1e878be16df7
linuxlinux>= f185de28d9ae6c978135993769352e523ee8df06 < 5da9a218340a2bc804dc4327e5804392e24a0b885da9a218340a2bc804dc4327e5804392e24a0b88
linuxlinux>= f185de28d9ae6c978135993769352e523ee8df06 < 17ef8efc00b34918b966388b2af0993811895a8c17ef8efc00b34918b966388b2af0993811895a8c
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.13 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.