PT-2024-6074 · Microsoft+5 · Windows 11+5

Published

2024-02-19

·

Updated

2025-03-28

·

CVE-2024-27405

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel's handling of Network Control Messages (NCMs) when used for tethering with Windows 11 as the host. In some cases, an extra byte is appended to the end of a properly parsed NCM, causing the kernel to treat it as a separate NCM and attempt to parse it. If this second NCM is faulty or corrupt, all previously parsed datagrams are dropped. This behavior has been observed with packets of sizes 1025 and 2048 bytes. According to the Windows driver, no Zero-Length Packet (ZLP) is needed if the block length is non-zero, as it already indicates the transfer size. However, some in-market NCM devices rely on ZLP when the block length is a multiple of the maximum packet size, leading to the kernel padding an extra zero at the end of the transfer to avoid being a multiple of the maximum packet size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06899
CVE-2024-27405
DLA-3840-1
DLA-3842-1
OESA-2024-1792
OESA-2024-1795
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6831-1
USN-6867-1
USN-6871-1
USN-6892-1
USN-6919-1

Affected Products

Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Windows 11