PT-2024-3378 · Linux+6 · Linux Kernel+6

Syzbot

·

Published

2024-01-18

·

Updated

2025-02-03

·

CVE-2024-26631

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a data-race condition in the ipv6 mc down function in the Linux kernel's IPv6 multicast implementation. This condition can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is caused by the idev->mc ifc count variable being written over without proper locking. To fix this issue, calls to mld ifc stop work() and mld gq stop work() are encapsulated with mutex lock() and mutex unlock() to ensure proper locking.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03650
CVE-2024-26631
INFSA-2024_9315
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6725-1
USN-6725-2
USN-6765-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu