CVE-2024-44945
published 2024-08-31CVE-2024-44945: In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink: Initialise extack before use in ACKs
Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.10.7-1 (forky) | linux 6.10.7-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= bf2ac490d28c21a349e9eef81edc45320fca4a3c < 3e03b536d9454c5802168b9e85248d456d3ff6a3 | 3e03b536d9454c5802168b9e85248d456d3ff6a3 |
| linux | linux | >= bf2ac490d28c21a349e9eef81edc45320fca4a3c < d1a7b382a9d3f0f3e5a80e0be2991c075fa4f618 | d1a7b382a9d3f0f3e5a80e0be2991c075fa4f618 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.10.7-1 | 6.10.7-1 |
| linux | linux_kernel | >= 0 < 6.10.7-1 | 6.10.7-1 |
| linux | linux_kernel | >= 6.10 < 6.10.7 | 6.10.7 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: netfilter: nfnetlink: Initialise extack before use in ACKs
vendor_redhat·2024-08-31·CVSS 7.8
CVE-2024-44945 [HIGH] CWE-908 kernel: netfilter: nfnetlink: Initialise extack before use in ACKs
kernel: netfilter: nfnetlink: Initialise extack before use in ACKs
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink: Initialise extack before use in ACKs
Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.
Statement: Assessed metadata without initialization may not be in controlled by the attacker and hence this C and I should be limited exploitable.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - N
Debian
CVE-2024-44945: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2024·CVSS 7.8
CVE-2024-44945 [HIGH] CVE-2024-44945: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.10.7-1)
sid: resolved (fixed in 6.10.7-1)
trixie: resolved (fixed in 6.10.7-1)
OSV
CVE-2024-44945: In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack init
osv·2024-08-31·CVSS 7.8
CVE-2024-44945 [HIGH] CVE-2024-44945: In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack init
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.
GHSA
GHSA-8q4v-68hv-v55c: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink: Initialise extack before use in ACKs
Add missing extack in
ghsa_unreviewed·2024-08-31
CVE-2024-44945 [HIGH] GHSA-8q4v-68hv-v55c: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink: Initialise extack before use in ACKs
Add missing extack in
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink: Initialise extack before use in ACKs
Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-31
Published