Bug 2280442 (CVE-2024-27394)
Summary: | CVE-2024-27394 kernel: tcp: Fix Use-After-Free in tcp_ao_connect_init | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Robb Gatica <rgatica> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | acaringi, allarkin, aquini, bhu, chwhite, cye, cyin, dbohanno, debarbos, dfreiber, drow, dvlasenk, esandeen, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lzampier, mleitner, mmilgram, mstowell, nmurray, ptalbert, rparrazo, rrobaina, rvrbovsk, rysulliv, scweaver, sidakwo, sukulkar, tglozar, tyberry, vkumar, wcosta, williams, wmealing, ycote, ykopkova, zhijwang |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kernel 6.8.9, kernel 6.9-rc6 | Doc Type: | If docs needed, set a value |
Doc Text: |
A use-after-free (UAF) vulnerability was found in the TCP implementation of the Linux kernel. This issue occurs when memory that has been deallocated is accessed or incorrectly, potentially leading to security risks, such as data corruption or arbitrary code execution.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2280443 | ||
Bug Blocks: | 2280439 |
Description
Robb Gatica
2024-05-14 23:36:52 UTC
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2280443] The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-27394 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built). |