cbcvebase.
CVE-2024-27417
published 2024-05-17

CVE-2024-27417: In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace provides a correct IFA_TARGET_NETNSID value but no IFA_ADDRESS and IFA_LOCAL attributes, inet6_rtm_getaddr() returns -EINVAL with an elevated "struct net" refcount.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 9d4ffb5b9d879a75e4f7460e8b10e756b4dfb1329d4ffb5b9d879a75e4f7460e8b10e756b4dfb132
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 810fa7d5e5202fcfb22720304b755f1bdfd4c174810fa7d5e5202fcfb22720304b755f1bdfd4c174
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 8a54834c03c30e549c33d5da0975f3e1454ec9068a54834c03c30e549c33d5da0975f3e1454ec906
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 1b0998fdd85776775d975d0024bca227597e836a1b0998fdd85776775d975d0024bca227597e836a
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 44112bc5c74e64f28f5a9127dc34066c7a09bd0f44112bc5c74e64f28f5a9127dc34066c7a09bd0f
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 33a1b6bfef6def2068c8703403759024ce17053e33a1b6bfef6def2068c8703403759024ce17053e
linuxlinux>= 6ecf4c37eb3e89b0832c9616089a5cdca3747da7 < 10bfd453da64a057bcfd1a49fb6b271c48653cdb10bfd453da64a057bcfd1a49fb6b271c48653cdb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.20 < 5.4.2715.4.271
linuxlinux_kernel>= 5.11 < 5.15.1515.15.151
linuxlinux_kernel>= 5.16 < 6.1.816.1.81
linuxlinux_kernel>= 5.5 < 5.10.2125.10.212
linuxlinux_kernel>= 6.2 < 6.6.216.6.21
linuxlinux_kernel>= 6.7 < 6.7.96.7.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.