cbcvebase.
CVE-2024-39504
published 2024-07-12

CVE-2024-39504: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: validate mandatory meta and payload Check for mandatory netlink…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.2th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: validate mandatory meta and payload Check for mandatory netlink attributes in payload and meta expression when used embedded from the inner expression, otherwise NULL pointer dereference is possible from userspace.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.7-1 (forky)linux 6.9.7-1 (forky)
linuxlinux
linuxlinux>= 3a07327d10a09379315c844c63f27941f5081e0a < b30669fdea0ca03aa22995e6c99f7e7d9dee89ffb30669fdea0ca03aa22995e6c99f7e7d9dee89ff
linuxlinux>= 3a07327d10a09379315c844c63f27941f5081e0a < 39323f54cad29602917848346c71b087da92a19d39323f54cad29602917848346c71b087da92a19d
linuxlinux>= 3a07327d10a09379315c844c63f27941f5081e0a < c4ab9da85b9df3692f861512fe6c9812f38b7471c4ab9da85b9df3692f861512fe6c9812f38b7471
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.