cbcvebase.
CVE-2024-36954
published 2024-05-30

CVE-2024-36954: In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, so move '*buf = NULL' after __skb_linearize(), so that the skb can be freed on the err path.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.235 < 4.154.15
linuxlinux>= 4.19.193 < 4.19.3144.19.314
linuxlinux>= 4.4.271 < 4.54.5
linuxlinux>= 4.9.271 < 4.104.10
linuxlinux>= 4b1761898861117c97066aea6c58f68a7787f0bf < 01cd1b7b685751ee422d00d050292a3d277652d601cd1b7b685751ee422d00d050292a3d277652d6
linuxlinux>= 5.10.42 < 5.10.2175.10.217
linuxlinux>= 5.12.9 < 5.135.13
linuxlinux>= 5.4.124 < 5.4.2765.4.276
linuxlinux>= 64d17ec9f1ded042c4b188d15734f33486ed9966 < 2f87fd9476cf9725d774e6dcb7d17859c6a6d1ae2f87fd9476cf9725d774e6dcb7d17859c6a6d1ae
linuxlinux>= 6da24cfc83ba4f97ea44fc7ae9999a006101755c < adbce6d20da6254c86425a8d4359b221b5ccbccdadbce6d20da6254c86425a8d4359b221b5ccbccd
linuxlinux>= b7df21cf1b79ab7026f545e7bf837bd5750ac026 < 42c8471b0566c7539e7dd584b4d0ebd3cec8cb2c42c8471b0566c7539e7dd584b4d0ebd3cec8cb2c
linuxlinux>= b7df21cf1b79ab7026f545e7bf837bd5750ac026 < d03a82f4f8144befdc10518e732e2a60b34c870ed03a82f4f8144befdc10518e732e2a60b34c870e
linuxlinux>= b7df21cf1b79ab7026f545e7bf837bd5750ac026 < 614c5a5ae45a921595952117b2e2bd4d4bf9b574614c5a5ae45a921595952117b2e2bd4d4bf9b574
linuxlinux>= b7df21cf1b79ab7026f545e7bf837bd5750ac026 < 3210d34fda4caff212cb53729e6bd46de604d5653210d34fda4caff212cb53729e6bd46de604d565
linuxlinux>= b7df21cf1b79ab7026f545e7bf837bd5750ac026 < 97bf6f81b29a8efaf5d0983251a7450e5794370d97bf6f81b29a8efaf5d0983251a7450e5794370d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.