CVE-2024-27417
MEDIUMLinux kernel - Info Disclosure
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace provides a correct IFA_TARGET_NETNSID value but no IFA_ADDRESS and IFA_LOCAL attributes, inet6_rtm_getaddr() returns -EINVAL with an elevated "struct net" refcount.
References (8)
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
1.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-401
Status
published
Affected Products (14)
linux/linux_kernel
< 5.4.271
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
debian/debian_linux
linux/Kernel
< 5.4.271linux
linux/Kernel
< 5.10.212linux
linux/Kernel
< 5.15.151linux
linux/Kernel
< 6.1.81linux
linux/Kernel
< 6.6.21linux
linux/Kernel
< 6.7.9linux
Timeline
Published
May 17, 2024
Tracked Since
Feb 18, 2026