CVE-2024-40993

MEDIUM

Linux Kernel - Use-After-Free in ip_set_dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all sets, we are either in pernet exit phase or are executing a "destroy all sets command" from userspace. The latter was taken into account in ip_set_dereference() (nfnetlink mutex is held), but the former was not. The patch adds the required check to rcu_dereference_protected() in ip_set_dereference().

Scores

CVSS v3 5.5
EPSS 0.0028
EPSS Percentile 20.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (17)
linux/Kernel 6.1.95 - 6.1.96linux
linux/Kernel 6.6.35 - 6.6.36linux
linux/Kernel 6.9.6 - 6.9.7linux
Linux/Linux 0f1bb77c6d837c9513943bc7c08f04c5cc5c6568 - 523bed6489e089dd8040e72453fb79da47b144c2
Linux/Linux 2ba35b37f780c6410bb4bba9c3072596d8576702 - 94dd411c18d7fff9e411555d5c662d29416501e4
Linux/Linux 390b353d1a1da3e9c6c0fd14fe650d69063c95d6 - 788d585e62f487bc4536d454937f737b70d39a33
Linux/Linux 4e7aaa6b82d63e8ddcbfb56b4fd3d014ca586f10 - 8ecd06277a7664f4ef018abae3abd3451d64e7a6
Linux/Linux 6.1.95 - 6.1.96
Linux/Linux 6.6.35 - 6.6.36
Linux/Linux 6.9.6 - 6.9.7
... and 7 more
Published Jul 12, 2024
Tracked Since Feb 18, 2026