PT-2024-26950 · Linux+9 · Linux Kernel+9

Syzbot

·

Published

2024-05-15

·

Updated

2025-09-29

·

CVE-2024-36286

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description A vulnerability has been resolved in the Linux kernel related to netfilter: nfnetlink queue, where the function nf reinject() could be called without acquiring rcu read lock(), leading to suspicious RCU usage. This issue was reported by syzbot and is associated with a WARNING message regarding suspicious RCU usage. The vulnerability is related to the instance destroy rcu() function and involves the nfqnl flush() and nfqnl reinject() functions. Technical details include the involvement of rcu lock acquire, rcu do batch, and rcu core functions, as well as spin lock bh and lockdep rcu suspicious functions.
Recommendations To resolve this issue, update the Linux kernel to version 6.6.37 or later. As a temporary workaround, consider restricting access to the nfnetlink queue module to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5101
ALSA-2024:5102
ALSA-2025_16880
BDU:2025-02943
CESA-2024_5101
CESA-2024_5102
CVE-2024-36286
DLA-3840-1
DSA-5730-1
INFSA-2024_5101
INFSA-2024_5102
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2030
OESA-2024-2076
OESA-2024-2321
OESA-2024-2322
OESA-2024-2324
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024_5101
RHSA-2024_5102
RLSA-2024:5101
RLSA-2024:5102
RXSA-2024:5101
SUSE-SU-2024:3189-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6953-1
USN-6979-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1
USN-7029-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu