CVE-2024-36009Linux vulnerability

16 documents8 sources
Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.0%
top 97.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateAug 13

Description

In the Linux kernel, the following vulnerability has been resolved: ax25: Fix netdev refcount issue The dev_tracker is added to ax25_cb in ax25_bind(). When the ax25 device is detaching, the dev_tracker of ax25_cb should be deallocated in ax25_kill_by_device() instead of the dev_tracker of ax25_dev. The log reported by ref_tracker is shown below: [ 80.884935] ref_tracker: reference already released. [ 80.885150] ref_tracker: allocated in: [ 80.885349] ax25_dev_device_up+0x105/0x540 [ 80.88573

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages11 packages

NVDlinux/linux_kernel4.14.2774.15+9
Debianlinux/linux_kernel< 6.1.90-1+2
Ubuntulinux/linux_kernel< 6.8.0-40.40
CVEListV5linux/linuxfeef318c855a361a1eccd880f33e88c460eb63b40d14f104027e30720582448706c7d6b43065c851+9
debiandebian/linux< linux 6.1.90-1 (bookworm)

Patches

🔴Vulnerability Details

7
OSV
linux-lowlatency, linux-raspi vulnerabilities2024-08-13
OSV
linux-azure vulnerabilities2024-08-13
OSV
linux-oem-6.8 vulnerabilities2024-08-12
OSV
linux-nvidia-lowlatency, linux-oracle vulnerabilities2024-08-09
OSV
linux, linux-aws, linux-gcp, linux-gke, linux-ibm, linux-nvidia, linux-nvidia-6.8 vulnerabilities2024-08-08

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2024-08-13
Ubuntu
Linux kernel (OEM) vulnerabilities2024-08-12
Ubuntu
Linux kernel vulnerabilities2024-08-09
Ubuntu
Linux kernel vulnerabilities2024-08-08
Red Hat
kernel: ax25: Fix netdev refcount issue2024-05-20

💬Community

1
Bugzilla
CVE-2024-36009 kernel: ax25: Fix netdev refcount issue2024-05-20