cbcvebase.
CVE-2024-36031
published 2024-05-30

CVE-2024-36031: In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is…

PriorityP340critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.75%
50.7th percentile
In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem for DNS resolution as the expiration set by user-space is overwritten to TIME64_MAX, disabling further DNS updates. Fix this by restoring the condition that key_set_expiry is only called when the pre-parser sets a specific expiry.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 2552b32b0b349df160a509fe49f5f308cb922f2b < ed79b93f725cd0da39a265dc23d77add1527b9beed79b93f725cd0da39a265dc23d77add1527b9be
linuxlinux>= 39299bdd2546688d92ed9db4948f6219ca1b9542 < 939a08bcd4334bad4b201e60bd0ae1f278d71d41939a08bcd4334bad4b201e60bd0ae1f278d71d41
linuxlinux>= 39299bdd2546688d92ed9db4948f6219ca1b9542 < cc219cb8afbc40ec100c0de941047bb29373126acc219cb8afbc40ec100c0de941047bb29373126a
linuxlinux>= 39299bdd2546688d92ed9db4948f6219ca1b9542 < 9da27fb65a14c18efd4473e2e82b76b53ba602529da27fb65a14c18efd4473e2e82b76b53ba60252
linuxlinux>= 5.10.206 < 5.10.2175.10.217
linuxlinux>= 5.15.146 < 5.15.1595.15.159
linuxlinux>= 6.1.70 < 6.1.916.1.91
linuxlinux>= 6.6.9 < 6.6.316.6.31
linuxlinux>= 791d5409cdb974c31a1bc7a903ea729ddc7d83df < e4519a016650e952ad9eb27937f8c447d5a4e06de4519a016650e952ad9eb27937f8c447d5a4e06d
linuxlinux>= 97be1e865e70e5a0ad0a5b5f5dca5031ca0b53ac < ad2011ea787928b2accb5134f1e423b11fe80a8aad2011ea787928b2accb5134f1e423b11fe80a8a
linuxlinux>= afc360e8a1256acb7579a6f5b6f2c30b85b39301 < 25777f3f4e1f371d16a594925f31e37ce07b6ec725777f3f4e1f371d16a594925f31e37ce07b6ec7
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.10.206 < 5.10.2175.10.217
linuxlinux_kernel>= 5.15.146 < 5.15.1595.15.159
linuxlinux_kernel>= 6.1.70 < 6.1.916.1.91
linuxlinux_kernel>= 6.6.9 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10
linuxlinux_kernel>= 6.9 < 6.9.16.9.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.