cbcvebase.
CVE-2024-35898
published 2024-05-19

CVE-2024-35898: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get()…

PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() nft_unregister_flowtable_type() within nf_flow_inet_module_exit() can concurrent with __nft_flowtable_type_get() within nf_tables_newflowtable(). And thhere is not any protection when iterate over nf_tables_flowtables list in __nft_flowtable_type_get(). Therefore, there is pertential data-race of nf_tables_flowtables list entry. Use list_for_each_entry_rcu() to iterate over nf_tables_flowtables list in __nft_flowtable_type_get(), and use rcu_read_lock() in the caller nft_flowtable_type_get() to protect the entire type query process.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < 69d1fe14a680042ec913f22196b58e2c8ff1b00769d1fe14a680042ec913f22196b58e2c8ff1b007
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < a347bc8e6251eaee4b619da28020641eb5b0dd77a347bc8e6251eaee4b619da28020641eb5b0dd77
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < 940d41caa71f0d3a52df2fde5fada524a993e331940d41caa71f0d3a52df2fde5fada524a993e331
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < 2485bcfe05ee3cf9ca8923a94fa2e456924c79c82485bcfe05ee3cf9ca8923a94fa2e456924c79c8
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < 9b5b7708ec2be21dd7ef8ca0e3abe4ae9f3b083b9b5b7708ec2be21dd7ef8ca0e3abe4ae9f3b083b
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < 8b891153b2e4dc0ca9d9dab8f619d49c740813df8b891153b2e4dc0ca9d9dab8f619d49c740813df
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < e684b1674fd1ca4361812a491242ae871d6b2859e684b1674fd1ca4361812a491242ae871d6b2859
linuxlinux>= 3b49e2e94e6ebb8b23d0955d9e898254455734f8 < 24225011d81b471acc0e1e315b7d9905459a630424225011d81b471acc0e1e315b7d9905459a6304
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 4.16 < 4.19.3124.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.856.1.85
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.