CVE-2024-46855: netfilter: nft_socket: fix sk refcount leaks
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftsocket: fix sk refcount leaks
We must put 'sk' reference before returning.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46855?
CVE-2024-46855 has a moderate severity rating due to potential impacts on system stability and security.
How do I fix CVE-2024-46855?
To address CVE-2024-46855, update the Linux kernel to versions 6.1.123-1, 6.1.119-1, or 6.12.11-1.
Which Linux kernel versions are affected by CVE-2024-46855?
CVE-2024-46855 affects multiple Linux kernel versions, including 4.19.76, 5.2.18, and versions between 5.3 and 6.11-rc7.
What is the nature of the vulnerability described in CVE-2024-46855?
CVE-2024-46855 involves reference count leaks in the netfilter nft_socket component of the Linux kernel.
Are there any known exploits for CVE-2024-46855?
As of now, there are no widely known exploits specifically targeting CVE-2024-46855 publicly available.