5.5
CVE-2024-41043
- EPSS 0.23%
- Veröffentlicht 29.07.2024 15:15:12
- Zuletzt bearbeitet 25.09.2025 20:04:09
- Erkennungen
netfilter: nfnetlink_queue: drop bogus WARN_ON
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: drop bogus WARN_ON Happens when rules get flushed/deleted while packet is out, so remove this WARN_ON. This WARN exists in one form or another since v4.14, no need to backport this to older releases, hence use a more recent fixes tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.9 < 6.9.10
Linux ≫ Linux Kernel Version 6.10 Update rc1
Linux ≫ Linux Kernel Version 6.10 Update rc2
Linux ≫ Linux Kernel Version 6.10 Update rc3
Linux ≫ Linux Kernel Version 6.10 Update rc4
Linux ≫ Linux Kernel Version 6.10 Update rc5
Linux ≫ Linux Kernel Version 6.10 Update rc6
Linux ≫ Linux Kernel Version 6.10 Update rc7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.137 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://git.kernel.org/stable/c/631a4b3ddc7831b20442c59c28b0476d0704c9af
https://git.kernel.org/stable/c/86858da8335db48bde9be02abd7156a69d622e86