cbcvebase.
CVE-2024-44986
published 2024-09-04

CVE-2024-44986: In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to make sure the dst and associated idev are alive.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.55 < 5.115.11
linuxlinux>= 5.13.7 < 5.145.14
linuxlinux>= 5.4.137 < 5.55.5
linuxlinux>= 5796015fa968a3349027a27dcd04c71d95c53ba5 < e891b36de161fcd96f12ff83667473e5067b9037e891b36de161fcd96f12ff83667473e5067b9037
linuxlinux>= 5796015fa968a3349027a27dcd04c71d95c53ba5 < 3574d28caf9a09756ae87ad1ea096c6f47b6101e3574d28caf9a09756ae87ad1ea096c6f47b6101e
linuxlinux>= 5796015fa968a3349027a27dcd04c71d95c53ba5 < 6ab6bf731354a6fdbaa617d1ec194960db61cf3b6ab6bf731354a6fdbaa617d1ec194960db61cf3b
linuxlinux>= 5796015fa968a3349027a27dcd04c71d95c53ba5 < 56efc253196751ece1fc535a5b582be127b0578a56efc253196751ece1fc535a5b582be127b0578a
linuxlinux>= 5796015fa968a3349027a27dcd04c71d95c53ba5 < da273b377ae0d9bd255281ed3c2adb228321687bda273b377ae0d9bd255281ed3c2adb228321687b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.10.55 < 5.10.2335.10.233
linuxlinux_kernel>= 5.13.7 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 5.4.137 < 5.4.2895.4.289

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.