cbcvebase.
CVE-2024-36946
published 2024-05-30

CVE-2024-36946: In the Linux kernel, the following vulnerability has been resolved: phonet: fix rtm_phonet_notify() skb allocation fill_route() stores three components in the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.3th percentile
In the Linux kernel, the following vulnerability has been resolved: phonet: fix rtm_phonet_notify() skb allocation fill_route() stores three components in the skb: - struct rtmsg - RTA_DST (u8) - RTA_OIF (u32) Therefore, rtm_phonet_notify() should use NLMSG_ALIGN(sizeof(struct rtmsg)) + nla_total_size(1) + nla_total_size(4)

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < ec1f71c05caeba0f814df77e0f511d8b4618623aec1f71c05caeba0f814df77e0f511d8b4618623a
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < dc6beac059f0331de97155a89d84058d4a9e49c7dc6beac059f0331de97155a89d84058d4a9e49c7
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < f085e02f0a32f6dfcfabc6535c9c4a1707cef86bf085e02f0a32f6dfcfabc6535c9c4a1707cef86b
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < 4ff334cade9dae50e4be387f71e94fae634aa9b44ff334cade9dae50e4be387f71e94fae634aa9b4
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < 728a83160f98ee6b60df0d890141b9b7240182fe728a83160f98ee6b60df0d890141b9b7240182fe
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < ee9e39a6cb3ca2a3d35b4ae25547ee3526a44d00ee9e39a6cb3ca2a3d35b4ae25547ee3526a44d00
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < 9a77226440008cf04ba68faf641a2d50f49981379a77226440008cf04ba68faf641a2d50f4998137
linuxlinux>= f062f41d06575744b9eaf725eef8a5d3b5f5b7ca < d8cac8568618dcb8a51af3db1103e8d4cc4aeea7d8cac8568618dcb8a51af3db1103e8d4cc4aeea7
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 2.6.33 < 4.19.3144.19.314
linuxlinux_kernel>= 4.20 < 5.4.2765.4.276
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.