PT-2024-21882 · Linux+3 · Linux Kernel+3

Published

2024-05-17

·

Updated

2026-05-26

·

CVE-2024-27418

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the mctp local output function in the Linux kernel, which only takes ownership of the skb on success. If mctp local output fails in specific states, it may leak an skb because the skb ownership is not transferred until the actual output routing occurs. To resolve this, the mctp local output function has been modified to free the skb on all error paths up to the route action, ensuring it always consumes the passed skb.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Information Disclosure

Memory Leak

Weakness Enumeration

Related Identifiers

AZL-42156
BDU:2025-13358
CVE-2024-27418
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse