PT-2024-8928 · Linux+5 · Linux Kernel+5
Guillaume Nault
·
Published
2024-05-10
·
Updated
2025-12-23
·
CVE-2024-38612
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to the
seg6 init() function in the Linux kernel's IPv6 implementation. Specifically, the error path of seg6 init() is incorrect when CONFIG IPV6 SEG6 LWTUNNEL is not defined, leading to a situation where genl unregister family() is not called if seg6 hmac init() fails. This problem exists since a specific commit and was exacerbated by another commit that replaced unregister pernet subsys() with genl unregister family() in the error path. The vulnerability could potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Ubuntu