cbcvebase.
CVE-2024-49952
published 2024-10-21

CVE-2024-49952: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: prevent nf_skb_duplicated corruption syzbot found that nf_dup_ipv4()…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: prevent nf_skb_duplicated corruption syzbot found that nf_dup_ipv4() or nf_dup_ipv6() could write per-cpu variable nf_skb_duplicated in an unsafe way [1]. Disabling preemption as hinted by the splat is not enough, we have to disable soft interrupts as well. [1] BUG: using __this_cpu_write() in preemptible [00000000] code: syz.4.282/6316 caller is nf_dup_ipv4+0x651/0x8f0 net/ipv4/netfilter/nf_dup_ipv4.c:87 CPU: 0 UID: 0 PID: 6316 Comm: syz.4.282 Not tainted 6.11.0-rc7-syzkaller-00104-g7052622fccb1 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024 Call Trace: __dump_stack lib/dump_stack.c:93 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119 check_preemption_disabled+0x10e/0x120 lib/smp_processor_id.c:49 nf_dup_ipv4+0x651/0x8f0 net/ipv4/netfilter/nf_dup_ipv4.c:87 nft_dup_ipv4_eval+0x1db/0x300 net/ipv4/netfilter/nft_dup_ipv4.c:30 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline] nft_do_chain+0x4ad/0x1da0 net/netfilter/nf_tables_core.c:288 nft_do_chain_ipv4+0x202/0x320 net/netfilter/nft_chain_filter.c:23 nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline] nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626 nf_hook+0x2c4/0x450 include/linux/netfilter.h:269 NF_HOOK_COND include/linux/netfilter.h:302 [inline] ip_output+0x185/0x230 net/ipv4/ip_output.c:433 ip_local_out net/ipv4/ip_output.c:129 [inline] ip_send_skb+0x74/0x100 net/ipv4/ip_output.c:1495 udp_send_skb+0xacf/0x1650 net/ipv4/udp.c:981 udp_sendmsg+0x1c21/0x2a60 net/ipv4/udp.c:1269 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x1a6/0x270 net/socket.c:745 ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597 ___sys_sendmsg net/socket.c:2651 [inline] __sys_sendmmsg+0x3b2/0x740 net/socket.c:2737 __do_sys_sendmmsg net/socket.c:2766 [inline] __se_sys_sendmmsg net/socket.c:2763 [inline] __x64_sys_sendmmsg+0xa0/0xb0 net/socket.c:2763 do_syscall_x64 arch/x86

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < 50067d8b3f48e4cd4c9e817d3e9a5b5ff3507ca750067d8b3f48e4cd4c9e817d3e9a5b5ff3507ca7
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < c0add6ed2cf1c4733cd489efc61faeccd3433b41c0add6ed2cf1c4733cd489efc61faeccd3433b41
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < 531754952f5dfc4b141523088147071d6e6112c4531754952f5dfc4b141523088147071d6e6112c4
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < 38e3fd0c4a2616052eb3c8f4e6f32d1ff47cd66338e3fd0c4a2616052eb3c8f4e6f32d1ff47cd663
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < b40b027a0c0cc1cb9471a13f9730bb2fff12a15bb40b027a0c0cc1cb9471a13f9730bb2fff12a15b
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < 4e3542f40f3a94efa59ea328e307c50601ed70654e3542f40f3a94efa59ea328e307c50601ed7065
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < f839c5cd348201fec440d987cbca9b979bdb4fa7f839c5cd348201fec440d987cbca9b979bdb4fa7
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < 752e1924604254f1708f3e3700283a86ebdd325d752e1924604254f1708f3e3700283a86ebdd325d
linuxlinux>= d877f07112f1e5a247c6b585c971a93895c9f738 < 92ceba94de6fb4cee2bf40b485979c342f44a49292ceba94de6fb4cee2bf40b485979c342f44a492
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.15.0-236.2484.15.0-236.248
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 4.3 < 4.19.3234.19.323

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.