PT-2024-3378 · Linux+6 · Linux Kernel+6
Syzbot
·
Published
2024-01-18
·
Updated
2025-02-03
·
CVE-2024-26631
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to a data-race condition in the
ipv6 mc down function in the Linux kernel's IPv6 multicast implementation. This condition can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is caused by the idev->mc ifc count variable being written over without proper locking. To fix this issue, calls to mld ifc stop work() and mld gq stop work() are encapsulated with mutex lock() and mutex unlock() to ensure proper locking.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Locking
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu