PT-2024-6548 · Linux+10 · Linux Kernel+10

Chengen Du

+1

·

Published

2024-07-11

·

Updated

2025-09-29

·

CVE-2024-41040

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a use-after-free vulnerability in the net/sched subsystem of the Linux kernel. Specifically, the tcf ct flow table process conn function may access memory after it has been freed, leading to a slab-use-after-free error. This can occur when a clash is resolved but the ct object is still passed to the tcf ct flow table process conn function for further processing. The vulnerability can be fixed by retrieving the ct object from the skb again after confirming the conntrack.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:6567
ALSA-2024:7000
ALSA-2024:7001
ALSA-2025_16880
ALT-PU-2024-10465
ALT-PU-2024-12537
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2024-07692
CESA-2024_7000
CESA-2024_7001
CVE-2024-41040
DLA-4008-1
DSA-5747-1
INFSA-2024_6567
INFSA-2024_7000
INFSA-2024_7001
MGASA-2024-0277
MGASA-2024-0278
OESA-2024-1960
OESA-2024-1962
OESA-2024-1964
OESA-2024-2258
OPENSUSE-SU-2024_2947-1
RHSA-2024:6567
RHSA-2024:7000
RHSA-2024:7001
RHSA-2024:8107
RHSA-2024_6567
RHSA-2024_7000
RHSA-2024_7001
RHSA-2025:0063
RHSA-2025:0064
RLSA-2024:6567
RLSA-2024:7001
RXSA-2024:6567
SUSE-SU-2024:2894-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu