cbcvebase.
CVE-2024-40993
published 2024-07-12

CVE-2024-40993: In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all sets, we…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all sets, we are either in pernet exit phase or are executing a "destroy all sets command" from userspace. The latter was taken into account in ip_set_dereference() (nfnetlink mutex is held), but the former was not. The patch adds the required check to rcu_dereference_protected() in ip_set_dereference().

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux>= 0f1bb77c6d837c9513943bc7c08f04c5cc5c6568 < 523bed6489e089dd8040e72453fb79da47b144c2523bed6489e089dd8040e72453fb79da47b144c2
linuxlinux>= 2ba35b37f780c6410bb4bba9c3072596d8576702 < 94dd411c18d7fff9e411555d5c662d29416501e494dd411c18d7fff9e411555d5c662d29416501e4
linuxlinux>= 390b353d1a1da3e9c6c0fd14fe650d69063c95d6 < 788d585e62f487bc4536d454937f737b70d39a33788d585e62f487bc4536d454937f737b70d39a33
linuxlinux>= 4e7aaa6b82d63e8ddcbfb56b4fd3d014ca586f10 < 8ecd06277a7664f4ef018abae3abd3451d64e7a68ecd06277a7664f4ef018abae3abd3451d64e7a6
linuxlinux>= 6.1.95 < 6.1.966.1.96
linuxlinux>= 6.6.35 < 6.6.366.6.36
linuxlinux>= 6.9.6 < 6.9.76.9.7
linuxlinux>= 90ae20d47de602198eb69e6cd7a3db3420abfc08 < 3fc09e1ca854bc234e007a56e0f7431f5e2defb53fc09e1ca854bc234e007a56e0f7431f5e2defb5
linuxlinux>= 93b53c202b51a69e42ca57f5a183f7e008e19f83 < 72d9611968867cc4c5509e7708b1507d692b797a72d9611968867cc4c5509e7708b1507d692b797a
linuxlinux>= c0761d1f1ce1d5b85b5e82bbb714df12de1aa8c3 < 3799d02ae4208af08e81310770d8754863a246a13799d02ae4208af08e81310770d8754863a246a1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.