cbcvebase.
CVE-2024-42269
published 2024-08-17

CVE-2024-42269: In the Linux kernel, the following vulnerability has been resolved: netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init(). ip6table_nat_table_init() accesses net->gen->ptr[ip6table_nat_net_ops.id], but the function is exposed to user space before the entry is allocated via register_pernet_subsys(). Let's call register_pernet_subsys() before xt_register_template().

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= fdacd57c79b79a03c7ca88f706ad9fb7b46831c1 < 419ee6274c5153b89c4393c1946faa4c3cad4f9e419ee6274c5153b89c4393c1946faa4c3cad4f9e
linuxlinux>= fdacd57c79b79a03c7ca88f706ad9fb7b46831c1 < 91b6df6611b7edb28676c4f63f90c56c30d3e60191b6df6611b7edb28676c4f63f90c56c30d3e601
linuxlinux>= fdacd57c79b79a03c7ca88f706ad9fb7b46831c1 < e85b9b6a87be4cb3710082038b677e97f2389003e85b9b6a87be4cb3710082038b677e97f2389003
linuxlinux>= fdacd57c79b79a03c7ca88f706ad9fb7b46831c1 < 87dba44e9471b79b255d0736858a897332db922687dba44e9471b79b255d0736858a897332db9226
linuxlinux>= fdacd57c79b79a03c7ca88f706ad9fb7b46831c1 < c22921df777de5606f1047b1345b8d22ef1c0b34c22921df777de5606f1047b1345b8d22ef1c0b34
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.15 < 6.1.1046.1.104
linuxlinux_kernel>= 6.2 < 6.6.456.6.45
linuxlinux_kernel>= 6.7 < 6.10.46.10.4
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.167.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.