CVE-2024-27419: netrom: Fix data-races around sysctl_net_busy_read
Published May 17, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
netrom: Fix data-races around sysctlnetbusyread
We need to protect the reader reading the sysctl value because the value can be changed concurrently.
Affected Software
21 affected componentsFixes available
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Linux Linux kernel>=2.6.13<4.19.310
Linux Linux kernel>=4.20<5.4.272
Linux Linux kernel>=5.5<5.10.213
Linux Linux kernel>=5.11<5.15.152
Linux Linux kernel>=5.16<6.1.82
Linux Linux kernel>=6.2<6.6.22
Linux Linux kernel>=6.7<6.7.10
Linux Linux kernel=2.6.12
Linux Linux kernel=2.6.12-rc2
Linux Linux kernel=2.6.12-rc3
Linux Linux kernel=2.6.12-rc4
Linux Linux kernel=2.6.12-rc5
Linux Linux kernel=6.8-rc1
Linux Linux kernel=6.8-rc2
Linux Linux kernel=6.8-rc3
Linux Linux kernel=6.8-rc4
Linux Linux kernel=6.8-rc5
Linux Linux kernel=6.8-rc6
Linux Linux kernel=6.8-rc7
Debian Debian Linux=10.0
Remediation
Event History
May 17, 2024
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
Description
Data Sourced
via NVD·12:15 PM
Description
Data Sourced
via NVD·12:15 PM
RemedySeverityWeaknessAffected Software
Jun 8, 2024
Data Sourced
via Launchpad·01:14 AM
Description
Apr 29, 2025
Data Sourced
via Ubuntu·06:17 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27419?
CVE-2024-27419 has a medium severity rating due to potential data races in the Linux kernel.
2
How do I fix CVE-2024-27419?
To fix CVE-2024-27419, upgrade to the patched versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
3
Which systems are affected by CVE-2024-27419?
CVE-2024-27419 affects the Linux kernel versions prior to the patched releases listed.
4
What kind of vulnerability is CVE-2024-27419?
CVE-2024-27419 is a data race vulnerability associated with sysctl value reading in the Linux kernel.
5
When was CVE-2024-27419 disclosed?
CVE-2024-27419 was disclosed in 2024 and addresses concurrency issues in the Linux kernel.