CVE-2024-40993Resource Injection in Linux

CWE-99Resource Injection5 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 92.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all sets, we are either in pernet exit phase or are executing a "destroy all sets command" from userspace. The latter was taken into account in ip_set_dereference() (nfnetlink mutex is held), but the former was not. The patch adds the required check to rcu_dereference_protected() in ip_set_dereference().

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianlinux/linux_kernel< 5.10.221-1+3
NVDlinux/linux_kernel4 versions+3
CVEListV5linux/linuxc0761d1f1ce1d5b85b5e82bbb714df12de1aa8c33799d02ae4208af08e81310770d8754863a246a1+9
debiandebian/linux< linux 6.1.99-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.99-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-66vv-cf65-88qw: In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all2024-07-12
OSV
CVE-2024-40993: In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all s2024-07-12

📋Vendor Advisories

2
Red Hat
kernel: netfilter: ipset: Fix suspicious rcu_dereference_protected()2024-07-12
Debian
CVE-2024-40993: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...2024