PT-2024-29223 · Linux+1 · Linux Kernel+1
Published
2024-07-11
·
Updated
2024-07-31
·
CVE-2024-41043
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to v4.14
Description
The issue occurs in the netfilter component of the Linux kernel, specifically in the nfnetlink queue module. It happens when rules are flushed or deleted while a packet is being processed, resulting in a bogus WARN ON message. This message has existed in some form since version v4.14.
Recommendations
For Linux kernel versions prior to v4.14, consider updating to a version that includes the fix for this issue. As a temporary workaround, it may be possible to minimize the occurrence of this issue by carefully managing rule flushes and deletions, although this is not a definitive solution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel