PT-2024-31312 · Linux+10 · Linux Kernel+10

Syzbot

·

Published

2024-08-02

·

Updated

2025-09-29

·

CVE-2024-44935

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.50
Description The issue is related to a null pointer dereference in the reuseport add sock() function. This occurs when two sockets concurrently call listen() and one of them is closed, causing the sk reuseport cb to be cleared. The problem arises because SCTP does not properly synchronize reuseport alloc(), reuseport add sock(), and reuseport detach sock(). To fix this, a locking strategy is applied to sctp hash endpoint() and sctp unhash endpoint(). The estimated number of potentially affected devices is not specified.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.50 or later. If updating is not possible, consider applying the locking strategy to sctp hash endpoint() and sctp unhash endpoint() as a temporary workaround. However, this should be done with caution and only by experienced developers, as it may introduce other issues. Restricting access to the vulnerable reuseport add sock() function can also be considered as a temporary mitigation measure until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8856
ALSA-2024:8870
ALSA-2025_16880
ALT-PU-2024-11345
ALT-PU-2024-11524
ALT-PU-2024-11855
ALT-PU-2024-11863
ALT-PU-2024-12232
ALT-PU-2024-12537
ALT-PU-2024-13121
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-48246
BDU:2025-01913
CESA-2024_8856
CESA-2024_8870
CVE-2024-44935
DLA-3912-1
DLA-4008-1
INFSA-2024_8856
INFSA-2024_8870
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2123
OESA-2024-2124
OESA-2024-2125
OESA-2024-2126
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
RHSA-2024:8856
RHSA-2024:8870
RHSA-2024_8856
RHSA-2024_8870
RHSA-2025:2270
RLSA-2024:8856
RLSA-2024:8870
SUSE-SU-2024:3551-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3592-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu