cbcvebase.
CVE-2024-27402
published 2024-05-17

CVE-2024-27402: In the Linux kernel, the following vulnerability has been resolved: phonet/pep: fix racy skb_queue_empty() use The receive queues are protected by their…

PriorityP422medium5.8CVSS 3.1
AVLACHPRLUINSUCLILAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: phonet/pep: fix racy skb_queue_empty() use The receive queues are protected by their respective spin-lock, not the socket lock. This could lead to skb_peek() unexpectedly returning NULL or a pointer to an already dequeued socket buffer.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 9641458d3ec42def729fde64669abf07f3220cd5 < 7d3914a477eed92b48c493a8631cc4554ab4fd4f7d3914a477eed92b48c493a8631cc4554ab4fd4f
linuxlinux>= 9641458d3ec42def729fde64669abf07f3220cd5 < 9d5523e065b568e79dfaa2ea1085a5bcf74baf789d5523e065b568e79dfaa2ea1085a5bcf74baf78
linuxlinux>= 9641458d3ec42def729fde64669abf07f3220cd5 < 0a9f558c72c47472c38c05fcb72c70abb91042770a9f558c72c47472c38c05fcb72c70abb9104277
linuxlinux>= 9641458d3ec42def729fde64669abf07f3220cd5 < 8ef4fcc7014b9f93619851d6b78d6cc2789a4c888ef4fcc7014b9f93619851d6b78d6cc2789a4c88
linuxlinux>= 9641458d3ec42def729fde64669abf07f3220cd5 < 7d2a894d7f487dcb894df023e9d3014cf5b93fe57d2a894d7f487dcb894df023e9d3014cf5b93fe5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 2.6.28 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.806.1.80
linuxlinux_kernel>= 6.2 < 6.6.196.6.19
linuxlinux_kernel>= 6.7 < 6.7.76.7.7

CVSS provenance

nvdv3.15.8MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.