PT-2024-29834 · Linux+8 · Linux Kernel+8

Published

2024-07-24

·

Updated

2025-09-29

·

CVE-2024-42283

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.50
Description The issue is related to the Linux kernel's net component, specifically with the initialization of fields in dumped nexthops. The struct nexthop grp contains two reserved fields that are not initialized by nla put nh group(), resulting in kernel memory leaks. These fields are not currently used but may complicate repurposing for new ends if not initialized properly. The leak can be observed using strace with commands like ip nexthop add and strace -e recvmsg ip nexthop get. The vulnerability may allow an attacker to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.50 or later. As a temporary workaround, consider restricting access to the net component or the nexthop functionality until a patch is available. Avoid using the recvmsg function with the ip nexthop get command until the issue is resolved.

Exploit

Fix

Use of Uninitialized Resource

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9605
ALSA-2024_9605
ALSA-2025_16880
ALT-PU-2024-11345
ALT-PU-2024-11524
ALT-PU-2024-11577
ALT-PU-2024-11855
ALT-PU-2024-11863
ALT-PU-2024-12232
ALT-PU-2024-12537
ALT-PU-2024-13121
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-47799
AZL-47838
BDU:2025-01445
CVE-2024-42283
DLA-3912-1
DLA-4008-1
INFSA-2024_9605
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2255
OESA-2024-2257
OESA-2024-2258
OESA-2024-2296
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:9605
RHSA-2024_9605
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu