CVE-2024-39504: netfilter: nft_inner: validate mandatory meta and payload
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftinner: validate mandatory meta and payload
Check for mandatory netlink attributes in payload and meta expression when used embedded from the inner expression, otherwise NULL pointer dereference is possible from userspace.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39504?
CVE-2024-39504 is classified as a high severity vulnerability due to the potential for NULL pointer dereference leading to denial of service.
How do I fix CVE-2024-39504?
To fix CVE-2024-39504, update to the kernel versions that are patched: 6.6.35, 6.9.6, 6.10, or the specific versions provided by your Linux distribution.
Which Linux kernel versions are affected by CVE-2024-39504?
CVE-2024-39504 affects the Linux kernel versions 6.2 through 6.6.34, 6.7 through 6.9.5, and 6.10-rc1, 6.10-rc2, and 6.10-rc3.
What components are vulnerable in CVE-2024-39504?
CVE-2024-39504 pertains to vulnerabilities in the netfilter component of the Linux kernel that allow improper validation of netlink attributes.
Is CVE-2024-39504 being actively exploited?
As of the latest information available, there is no specific indication that CVE-2024-39504 is being actively exploited in the wild.