cbcvebase.
CVE-2024-41044
published 2024-07-29

CVE-2024-41044: In the Linux kernel, the following vulnerability has been resolved: ppp: reject claimed-as-LCP but actually malformed packets Since 'ppp_async_encode()'…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
20.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ppp: reject claimed-as-LCP but actually malformed packets Since 'ppp_async_encode()' assumes valid LCP packets (with code from 1 to 7 inclusive), add 'ppp_check_packet()' to ensure that LCP packet has an actual body beyond PPP_LCP header bytes, and reject claimed-as-LCP but actually malformed data otherwise.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 97d1efd8be26615ff680cdde86937d5943138f3797d1efd8be26615ff680cdde86937d5943138f37
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6e8f1c21174f9482033bbb59f13ce1a8cbe843c36e8f1c21174f9482033bbb59f13ce1a8cbe843c3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3ba12c2afd933fc1bf800f6d3f6c7ec8f602ce563ba12c2afd933fc1bf800f6d3f6c7ec8f602ce56
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ebc5c630457783d17d0c438b0ad70b232a64a82febc5c630457783d17d0c438b0ad70b232a64a82f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3134bdf7356ed952dcecb480861d2afcc1e404923134bdf7356ed952dcecb480861d2afcc1e40492
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 099502ca410922b56353ccef2749bc0de669da78099502ca410922b56353ccef2749bc0de669da78
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d683e7f3fc48f59576af34631b4fb07fd931343ed683e7f3fc48f59576af34631b4fb07fd931343e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f2aeb7306a898e1cbd03963d376f4b6656ca2b55f2aeb7306a898e1cbd03963d376f4b6656ca2b55
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 2.6.13 < 4.19.3184.19.318
linuxlinux_kernel>= 4.20 < 5.4.2805.4.280
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.1006.1.100
linuxlinux_kernel>= 5.5 < 5.10.2225.10.222

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.