CVE-2024-40940

HIGH

Linux Kernel 5.19-6.1.95, 6.2-6.6.35, 6.7-6.9.6 - Use-After-Free in Flow Rule Creation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix tainted pointer delete is case of flow rules creation fail In case of flow rule creation fail in mlx5_lag_create_port_sel_table(), instead of previously created rules, the tainted pointer is deleted deveral times. Fix this bug by using correct flow rules pointers. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-415
Status published
Products (15)
linux/Kernel 5.19.0 - 6.1.95linux
linux/Kernel 6.2.0 - 6.6.35linux
linux/Kernel 6.7.0 - 6.9.6linux
Linux/Linux < 5.19
Linux/Linux 352899f384d4aefa77ede6310d08c1b515612a8f - 229bedbf62b13af5aba6525ad10b62ad38d9ccb5
Linux/Linux 352899f384d4aefa77ede6310d08c1b515612a8f - 531eab2da27dd42d68dfb841d82e987f4a6738b8
Linux/Linux 352899f384d4aefa77ede6310d08c1b515612a8f - a03a3fa12769e25f4385bee587afe1445aee7f7a
Linux/Linux 352899f384d4aefa77ede6310d08c1b515612a8f - d857df86837ac1c30592e8a068204d16feac9930
Linux/Linux 5.19
Linux/Linux 6.1.95 - 6.1.*
... and 5 more
Published Jul 12, 2024
Tracked Since Feb 18, 2026