#VU94267 Improper locking in Linux kernel


Vulnerability identifier: #VU94267

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-40995

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the tcf_idr_check_alloc() and rcu_read_unlock() functions in net/sched/act_api.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/0d8a2d287c8a394c0d4653f0c6c7be4c688e5a74
http://git.kernel.org/stable/c/c6a7da65a296745535a964be1019ec7691b0cb90
http://git.kernel.org/stable/c/25987a97eec4d5f897cd04ee1b45170829c610da
http://git.kernel.org/stable/c/6fc78d67f51aeb9a542d39a8714e16bc411582d4
http://git.kernel.org/stable/c/5f926aa96b08b6c47178fe1171e7ae331c695fc2
http://git.kernel.org/stable/c/7a0e497b597df7c4cf2b63fc6e9188b6cabe5335
http://git.kernel.org/stable/c/d864319871b05fadd153e0aede4811ca7008f5d6


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability