cbcvebase.
CVE-2024-42272
published 2024-08-17

CVE-2024-42272: In the Linux kernel, the following vulnerability has been resolved: sched: act_ct: take care of padding in struct zones_ht_key Blamed commit increased lookup…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: sched: act_ct: take care of padding in struct zones_ht_key Blamed commit increased lookup key size from 2 bytes to 16 bytes, because zones_ht_key got a struct net pointer. Make sure rhashtable_lookup() is not using the padding bytes which are not initialized. BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline] BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline] BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline] BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline] BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329 rht_ptr_rcu include/linux/rhashtable.h:376 [inline] __rhashtable_lookup include/linux/rhashtable.h:607 [inline] rhashtable_lookup include/linux/rhashtable.h:646 [inline] rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline] tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329 tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408 tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425 tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488 tcf_action_add net/sched/act_api.c:2061 [inline] tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118 rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647 netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550 rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665 netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline] netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357 netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x30f/0x380 net/socket.c:745 ____sys_sendmsg+0x877/0xb60 net/socket.c:2597 ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651 __sys_sendmsg net/socket.c:2680 [inline] __do_sys_sendmsg net/socket.c:2689 [inline] __se_sys_sendmsg net/socket.c:2687 [inline] __x64_sys_sendmsg+0x307/0x4a0 ne

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 03f625505e27f709390a86c9b78d3707f4c23df8 < 7c03ab555eb1ba26c77fd7c25bdf44a0ac23edee7c03ab555eb1ba26c77fd7c25bdf44a0ac23edee
linuxlinux>= 2f82f75f843445daa81e8b2a76774b1348033ce6 < d06daf0ad645d9225a3ff6958dd82e1f3988fa64d06daf0ad645d9225a3ff6958dd82e1f3988fa64
linuxlinux>= 5.10.221 < 5.10.2245.10.224
linuxlinux>= 5.15.162 < 5.15.1655.15.165
linuxlinux>= 6.1.96 < 6.1.1046.1.104
linuxlinux>= 6.6.36 < 6.6.456.6.45
linuxlinux>= 6.9.7 < 6.106.10
linuxlinux>= 88c67aeb14070bab61d3dd8be96c8b42ebcaf53a < 3a5b68869dbe14f1157c6a24ac71923db060eeab3a5b68869dbe14f1157c6a24ac71923db060eeab
linuxlinux>= 88c67aeb14070bab61d3dd8be96c8b42ebcaf53a < 2191a54f63225b548fd8346be3611c3219a247382191a54f63225b548fd8346be3611c3219a24738
linuxlinux>= 9126fd82e9edc7b4796f756e4b258d34f17e5e4a < d7cc186d0973afce0e1237c37f7512c01981fb79d7cc186d0973afce0e1237c37f7512c01981fb79
linuxlinux>= aa1f81fe3a059bc984b230b5352ab89d06aa3c7b < 3ddefcb8f75e312535e2e7d5fef9932019ba60f23ddefcb8f75e312535e2e7d5fef9932019ba60f2
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.10.221 < 5.10.2245.10.224
linuxlinux_kernel>= 5.15.162 < 5.15.1655.15.165
linuxlinux_kernel>= 6.1.96 < 6.1.1046.1.104

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.