cbcvebase.
CVE-2024-44987
published 2024-09-04

CVE-2024-44987: In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reported an UAF in ip6_send_skb() [1] After…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reported an UAF in ip6_send_skb() [1] After ip6_local_out() has returned, we no longer can safely dereference rt, unless we hold rcu_read_lock(). A similar issue has been fixed in commit a688caa34beb ("ipv6: take rcu lock in rawv6_send_hdrinc()") Another potential issue in ip6_finish_output2() is handled in a separate patch. [1] BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964 Read of size 8 at addr ffff88806dde4858 by task syz.1.380/6530 CPU: 1 UID: 0 PID: 6530 Comm: syz.1.380 Not tainted 6.11.0-rc3-syzkaller-00306-gdf6cbc62cc9b #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024 Call Trace: __dump_stack lib/dump_stack.c:93 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964 rawv6_push_pending_frames+0x75c/0x9e0 net/ipv6/raw.c:588 rawv6_sendmsg+0x19c7/0x23c0 net/ipv6/raw.c:926 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x1a6/0x270 net/socket.c:745 sock_write_iter+0x2dd/0x400 net/socket.c:1160 do_iter_readv_writev+0x60a/0x890 vfs_writev+0x37c/0xbb0 fs/read_write.c:971 do_writev+0x1b1/0x350 fs/read_write.c:1018 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f936bf79e79 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f936cd7f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000014 RAX: ffffffffffffffda RBX: 00007f936c115f80 RCX: 00007f936bf79e79 RDX: 0000000000000001 RSI: 0000000020000040 RDI: 0

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < 571567e0277008459750f0728f246086b2659429571567e0277008459750f0728f246086b2659429
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < ce2f6cfab2c637d0bd9762104023a15d0ab7c0a8ce2f6cfab2c637d0bd9762104023a15d0ab7c0a8
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < cb5880a0de12c7f618d2bdd84e2d985f1e06ed7ecb5880a0de12c7f618d2bdd84e2d985f1e06ed7e
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < 24e93695b1239fbe4c31e224372be77f82dab69a24e93695b1239fbe4c31e224372be77f82dab69a
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < 9a3e55afa95ed4ac9eda112d4f918af645d72f259a3e55afa95ed4ac9eda112d4f918af645d72f25
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < af1dde074ee2ed7dd5bdca4e7e8ba17f44e7b011af1dde074ee2ed7dd5bdca4e7e8ba17f44e7b011
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < e44bd76dd072756e674f45c5be00153f4ded68b2e44bd76dd072756e674f45c5be00153f4ded68b2
linuxlinux>= 0625491493d9000e4556bf566d205c28c8e7dc4e < faa389b2fbaaec7fd27a390b4896139f9da662e3faa389b2fbaaec7fd27a390b4896139f9da662e3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 2.6.32 < 4.19.3214.19.321
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.