PT-2024-4101 · Linux+9 · Linux Kernel+9

Sam Page

+1

·

Published

2024-05-01

·

Updated

2025-09-29

·

CVE-2024-36886

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 6.8.2
Description The vulnerability is related to a Use-After-Free (UAF) bug in the tipc buf append() function in the Linux kernel's Transparent Inter-Process Communication (TIPC) module. This bug can be exploited to execute arbitrary code, potentially leading to a remote code execution vulnerability. The issue arises from a slab-use-after-free error in the kfree skb list reason() function.
Recommendations To resolve this issue, update the Linux Kernel to a version that includes the fix for this vulnerability. Specifically, versions prior to 6.8.2 are affected, so updating to 6.8.2 or later should mitigate this vulnerability. As a temporary workaround, consider disabling the tipc buf append() function until a patch is available. However, this may have implications for the functionality of the TIPC module and should be carefully considered before implementation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4583
ALSA-2024:5101
ALSA-2024:5102
ALSA-2025_16880
BDU:2024-04552
CESA-2024_5101
CESA-2024_5102
CESA-2024_5522
CVE-2024-36886
DLA-3840-1
DLA-3843-1
DSA-5703-1
INFSA-2024_4583
INFSA-2024_5101
INFSA-2024_5102
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1706
OESA-2024-1707
OESA-2024-1736
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
RHSA-2024:4447
RHSA-2024:4533
RHSA-2024:4547
RHSA-2024:4548
RHSA-2024:4554
RHSA-2024:4583
RHSA-2024:4713
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024:5255
RHSA-2024:5256
RHSA-2024:5257
RHSA-2024:5520
RHSA-2024:5522
RHSA-2024:5858
RHSA-2024:7002
RHSA-2024:7003
RHSA-2024:7427
RHSA-2024_4583
RHSA-2024_5101
RHSA-2024_5102
RLSA-2024:4583
RLSA-2024:5101
RLSA-2024:5102
RXSA-2024:5101
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4367-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:0035-1
SUSE-SU-2025:0236-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
SUSE-SU-2025_0236-1
USN-6949-1
USN-6949-2
USN-6950-1
USN-6950-2
USN-6950-3
USN-6950-4
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6952-1
USN-6952-2
USN-6953-1
USN-6955-1
USN-6956-1
USN-6957-1
USN-6979-1
USN-7019-1
USN-7332-1
USN-7332-2
USN-7332-3
USN-7342-1
USN-7344-1
USN-7344-2
ZDI-24-821

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu