Fiche vulnérabilité
CVE-2024-56637 : faille moyenne linux linux kernel (CVSS 4.7)
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Hold module reference while requesting a module User space may unload ip_set.ko while it is itself requesting a set type backend module, leading to a kernel crash. The race condition may be provoked by inserting an mdelay() right after the nfnl_unlock() call.
En bref
- Sévérité
- Moyenne (CVSS 4.7)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 27 déc. 2024
- Dernière mise à jour
- 4 août 2026
Produits concernés
- linux linux kernel
Références
- Fiche CVE-2024-56637 sur le NVD (NIST)
- git.kernel.org/stable/c/0e67805e805c1f3edd6f43adbe08ea14b5526…
- git.kernel.org/stable/c/456f010bfaefde84d3390c755eedb1b0a5857…
- git.kernel.org/stable/c/5bae60a933ba5d16eed55c6b279be51bcbbc7…
- git.kernel.org/stable/c/6099b5d3e37145484fac4b8b4070c3f1abfb3…
- git.kernel.org/stable/c/90bf312a6b6b3d6012137f6776a4052ee85e0…
- git.kernel.org/stable/c/ba5e070f36682d07ca7ad2a953e6c9d96be19…
- git.kernel.org/stable/c/e5e2d3024753fdaca818b822e3827614bacbd…
- lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- lists.debian.org/debian-lts-announce/2025/03/msg00002.html