PT-2024-8435 · Linux+8 · Linux Kernel+8

Pablo Neira Ayuso

·

Published

2024-02-28

·

Updated

2026-03-14

·

CVE-2024-27415

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The vulnerability is related to the netfilter component in the Linux kernel, specifically with the bridge functionality. It occurs when the conntrack nf confirm logic cannot handle cloned skbs referencing the same nf conn entry, which happens for multicast or broadcast frames on bridges. This can lead to a race condition between the Macvlan broadcast worker and the normal confirm path. To work around this problem, explicit confirmation of the entry at LOCAL IN time is required before the upper layer has a chance to clone the unconfirmed entry. However, this workaround disables NAT and conntrack helpers. An alternative fix would be to add locking to all code parts that deal with unconfirmed packets, but this opens up other problems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Locking

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5928
ALSA-2025_16880
BDU:2024-09994
CVE-2024-27415
INFSA-2024_5928
OESA-2024-1694
OESA-2024-1706
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
RHSA-2024:5928
RHSA-2024:7489
RHSA-2024:7490
RHSA-2024_5928
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025:20343-1
SUSE-SU-2025:20344-1
SUSE-SU-2025:20354-1
SUSE-SU-2025:20355-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6871-1
USN-6892-1
USN-6919-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu