cbcvebase.
CVE-2024-53141
published 2024-12-06

CVE-2024-53141: In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
32.4th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefore, the range check for ip should be done later, but this part is missing and it seems that the vulnerability occurs. So we should add missing range checks and remove unnecessary range checks.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 3c20b5948f119ae61ee35ad8584d666020c915813c20b5948f119ae61ee35ad8584d666020c91581
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 78b0f2028f1043227a8eb0c41944027fc6a0459678b0f2028f1043227a8eb0c41944027fc6a04596
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 2e151b8ca31607d14fddc4ad0f14da0893e1a7c72e151b8ca31607d14fddc4ad0f14da0893e1a7c7
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < e67471437ae9083fa73fa67eee1573fec1b7c8cfe67471437ae9083fa73fa67eee1573fec1b7c8cf
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 7ffef5e5d5eeecd9687204a5ec2d863752aafb7e7ffef5e5d5eeecd9687204a5ec2d863752aafb7e
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 856023ef032d824309abd5c747241dffa33aae8c856023ef032d824309abd5c747241dffa33aae8c
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 591efa494a1cf649f50a35def649c43ae984cd03591efa494a1cf649f50a35def649c43ae984cd03
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 15794835378ed56fb9bacc6a5dd3b9f33520604e15794835378ed56fb9bacc6a5dd3b9f33520604e
linuxlinux>= 72205fc68bd13109576aa6c4c12c740962d28a6c < 35f56c554eb1b56b77b3cf197a6b00922d49033d35f56c554eb1b56b77b3cf197a6b00922d49033d
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-205.2255.4.0-205.225
linuxlinux_kernel>= 0 < 5.15.0-131.1415.15.0-131.141
linuxlinux_kernel>= 0 < 6.8.0-52.536.8.0-52.53
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 3.13.0-202.2533.13.0-202.253
linuxlinux_kernel>= 0 < 4.4.0-263.2974.4.0-263.297
linuxlinux_kernel>= 0 < 4.15.0-233.2454.15.0-233.245
linuxlinux_kernel>= 2.6.39 < 4.19.3254.19.325

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.