PT-2024-8501 · Linux+9 · Linux Kernel+9

Cosmin Ratiu

·

Published

2024-04-10

·

Updated

2025-09-29

·

CVE-2024-35960

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the incorrect initialization of resources in the add rule fg() function, which can lead to a crash when the flow group is deleted. This happens because create flow handle tries to find and reference existing identical rules, while add rule fg only adds new rules with a refcount of 1 to the tree. As a result, a rule with a refcount of 2 may not be linked into the tree, causing a crash when del sw hw rule is invoked. This issue has been observed in the wild due to another bug related to incorrect handling of duplicate pkt reformat ids.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4349
ALSA-2024:4352
ALSA-2024_4211
ALSA-2024_4349
ALSA-2024_4352
ALSA-2025_16880
BDU:2024-10061
CESA-2024_4211
CESA-2024_4352
CVE-2024-35960
DLA-3840-1
DLA-3842-1
ELSA-2024-4211
ELSA-2024-4349
INFSA-2024_4211
INFSA-2024_4349
INFSA-2024_4352
OESA-2024-1692
OESA-2024-1693
OESA-2024-1694
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
RHSA-2024:4106
RHSA-2024:4108
RHSA-2024:4211
RHSA-2024:4349
RHSA-2024:4352
RHSA-2024:4740
RHSA-2024:4902
RHSA-2024_4211
RHSA-2024_4349
RHSA-2024_4352
RLSA-2024:4211
RLSA-2024:4349
RLSA-2024:4352
RLSA-2024_4211
RLSA-2024_4349
RLSA-2024_4352
RXSA-2024:4211
RXSA-2024:4349
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2973-1
SUSE-SU-2024_2135-1
SUSE-SU-2024_2203-1
SUSE-SU-2024_2372-1
SUSE-SU-2024_2381-1
SUSE-SU-2024_2394-1
SUSE-SU-2024_2939-1
SUSE-SU-2024_2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1
USN-7428-1
USN-7428-2

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu