cbcvebase.
CVE-2024-42247
published 2024-08-07

CVE-2024-42247: In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel warnings because swap_endian() tries to load a 128-bit IPv6 address from an unaligned memory location: Kernel: unaligned access to 0x55f4688c in wg_allowedips_insert_v6+0x2c/0x80 [wireguard] (iir 0xf3010df) Kernel: unaligned access to 0x55f46884 in wg_allowedips_insert_v6+0x38/0x80 [wireguard] (iir 0xf2010dc) Avoid such unaligned memory accesses by instead using the get_unaligned_be64() helper macro. [Jason: replace src[8] in original patch with src+8]

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < ae630de24efb123d7199a43256396d7758f4cb75ae630de24efb123d7199a43256396d7758f4cb75
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < b4764f0ad3d68de8a0b847c05f427afb86dd54e6b4764f0ad3d68de8a0b847c05f427afb86dd54e6
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 217978a29c6ceca76d3c640bf94bdf50c268d801217978a29c6ceca76d3c640bf94bdf50c268d801
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 6638a203abad35fa636d59ac47bdbc4bc100fd746638a203abad35fa636d59ac47bdbc4bc100fd74
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 2fb34bf76431e831f9863cd59adc0bd1f67b0fbf2fb34bf76431e831f9863cd59adc0bd1f67b0fbf
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 948f991c62a4018fb81d85804eeab3029c6209f8948f991c62a4018fb81d85804eeab3029c6209f8
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.1006.1.100
linuxlinux_kernel>= 5.6 < 5.10.2225.10.222
linuxlinux_kernel>= 6.2 < 6.6.416.6.41
linuxlinux_kernel>= 6.7 < 6.9.106.9.10
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0
msrccbl2_kernel_5.15.162.2-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.164.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.