CVE-2024-27403

MEDIUM

Linux Kernel 4.16-5.15.150, 5.16-6.1.80, 6.2-6.6.19, 6.7-6.7.7 - Use-After-Free in nft_flow_offload Route Object

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: reset dst in route object after setting up flow dst is transferred to the flow object, route object does not own it anymore. Reset dst in route object, otherwise if flow_offload_add() fails, error path releases dst twice, leading to a refcount underflow.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (18)
linux/Kernel 4.16.0 - 5.15.150linux
linux/Kernel 5.16.0 - 6.1.80linux
linux/Kernel 6.2.0 - 6.6.19linux
linux/Kernel 6.7.0 - 6.7.7linux
Linux/Linux < 4.16
Linux/Linux 4.16
Linux/Linux 5.15.150 - 5.15.*
Linux/Linux 6.1.80 - 6.1.*
Linux/Linux 6.6.19 - 6.6.*
Linux/Linux 6.7.7 - 6.7.*
... and 8 more
Published May 17, 2024
Tracked Since Feb 18, 2026