cbcvebase.
CVE-2024-36929
published 2024-05-30

CVE-2024-36929: In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.90%
56.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb_copy_expand, in order to prevent a crash on a potential later call to skb_gso_segment.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 < faa83a7797f06cefed86731ba4baa3b4dfdc06c1faa83a7797f06cefed86731ba4baa3b4dfdc06c1
linuxlinux>= 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 < c7af99cc21923a9650533c9d77265c8dd683a533c7af99cc21923a9650533c9d77265c8dd683a533
linuxlinux>= 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 < 989bf6fd1e1d058e73a364dce1a0c53d33373f62989bf6fd1e1d058e73a364dce1a0c53d33373f62
linuxlinux>= 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 < cfe34d86ef9765c388f145039006bb79b6c81ac6cfe34d86ef9765c388f145039006bb79b6c81ac6
linuxlinux>= 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 < aea5e2669c2863fdd8679c40ee310b3bcaa85aecaea5e2669c2863fdd8679c40ee310b3bcaa85aec
linuxlinux>= 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 < d091e579b864fa790dd6a0cd537a22c383126681d091e579b864fa790dd6a0cd537a22c383126681
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 5.6 < 5.10.2175.10.217
linuxlinux_kernel>= 6.2 < 6.6.316.6.31

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.