CVE-2024-35857

MEDIUM

Linux Kernel 5.13-5.15.157, 5.16-6.1.89, 6.2-6.6.29, 6.7-6.8.8 - NULL Pointer Dereference in icmp_build_probe

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possible NULL dereferences from icmp_build_probe() First problem is a double call to __in_dev_get_rcu(), because the second one could return NULL. if (__in_dev_get_rcu(dev) && __in_dev_get_rcu(dev)->ifa_list) Second problem is a read from dev->ip6_ptr with no NULL check: if (!list_empty(&rcu_dereference(dev->ip6_ptr)->addr_list)) Use the correct RCU API to fix these. v2: add missing include <net/addrconf.h>

Scores

CVSS v3 5.3
EPSS 0.0089
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (18)
linux/Kernel 5.13.0 - 5.15.158linux
linux/Kernel 5.16.0 - 6.1.90linux
linux/Kernel 6.2.0 - 6.6.30linux
linux/Kernel 6.7.0 - 6.8.9linux
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.158 - 5.15.*
Linux/Linux 6.1.90 - 6.1.*
Linux/Linux 6.6.30 - 6.6.*
Linux/Linux 6.8.9 - 6.8.*
... and 8 more
Published May 17, 2024
Tracked Since Feb 18, 2026