CVE-2024-46771Use After Free in Linux

CWE-416Use After Free56 documents7 sources
Severity
5.5MEDIUMNVD
OSV8.8OSV7.8OSV7.1
EPSS
0.0%
top 99.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: can: bcm: Remove proc entry when dev is unregistered. syzkaller reported a warning in bcm_connect() below. [0] The repro calls connect() to vxcan1, removes vxcan1, and calls connect() with ifindex == 0. Calling connect() for a BCM socket allocates a proc entry. Then, bcm_sk(sk)->bound is set to 1 to prevent further connect(). However, removing the bound device resets bcm_sk(sk)->bound to 0 in bcm_notify(). The 2nd connect(

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel2.6.254.19.322+7
Debianlinux/linux_kernel< 5.10.226-1+3
Ubuntulinux/linux_kernel< 5.4.0-200.220+4
CVEListV5linux/linuxffd980f976e7fd666c2e61bf8ab35107efd118285c680022c4e28ba18ea500f3e29f0428271afa92+8
debiandebian/linux< linux 6.1.112-1 (bookworm)

Patches

🔴Vulnerability Details

27
OSV
linux-lts-xenial vulnerabilities2025-05-13
OSV
linux-fips vulnerabilities2025-05-12
OSV
linux-aws vulnerabilities2025-05-12
OSV
linux, linux-aws, linux-kvm vulnerabilities2025-05-12
OSV
linux-aws-fips, linux-fips, linux-gcp-fips vulnerabilities2025-05-07

📋Vendor Advisories

28
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2025-05-13
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-05-12
Ubuntu
Linux kernel vulnerabilities2025-05-12
Ubuntu
Linux kernel (AWS) vulnerabilities2025-05-12