First published: Mon Jul 29 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times.
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=3.0<4.19.318 | |
Linux Kernel | >=4.20<5.4.280 | |
Linux Kernel | >=5.5<5.10.222 | |
Linux Kernel | >=5.11<5.15.163 | |
Linux Kernel | >=5.16<6.1.100 | |
Linux Kernel | >=6.2<6.6.41 | |
Linux Kernel | >=6.7<6.9.10 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 | |
debian/linux-6.1 | 6.1.128-1~deb11u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41046 has a high severity rating due to a double free vulnerability in the Linux kernel.
To fix CVE-2024-41046, update your Linux kernel to the latest stable version, such as 5.10.223-1 or higher.
CVE-2024-41046 affects multiple Linux kernel versions between 3.0 and 6.6.41.
This vulnerability can lead to unexpected system crashes or potential remote code execution if exploited.
Yes, patches are available in updated versions of the Linux kernel, such as those released by Debian.