PT-2024-8928 · Linux+5 · Linux Kernel+5

Guillaume Nault

·

Published

2024-05-10

·

Updated

2025-12-23

·

CVE-2024-38612

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the seg6 init() function in the Linux kernel's IPv6 implementation. Specifically, the error path of seg6 init() is incorrect when CONFIG IPV6 SEG6 LWTUNNEL is not defined, leading to a situation where genl unregister family() is not called if seg6 hmac init() fails. This problem exists since a specific commit and was exacerbated by another commit that replaced unregister pernet subsys() with genl unregister family() in the error path. The vulnerability could potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-10602
CVE-2024-38612
DLA-3840-1
DSA-5730-1
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2292
OESA-2024-2293
OESA-2024-2294
OESA-2024-2295
OESA-2024-2296
RHSA-2024:9315
RHSA-2024_9315
USN-6949-1
USN-6949-2
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6952-1
USN-6952-2
USN-6953-1
USN-6955-1
USN-6979-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7009-1
USN-7009-2
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Ubuntu