VDB

CISA-2024-42269

CISA-2024-42269 PUBLISHED

Reported by Linux · Published August 17, 2024

In the Linux kernel, the following vulnerability has been resolved: netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init(). ip6table_nat_table_init() accesses net->gen->ptr[ip6table_nat_net_ops.id], but the function is exposed to user space before the entry is allocated via register_pernet_subsys(). Let's call register_pernet_subsys() before xt_register_template().

Affected Products

VendorProductVersions
LinuxLinuxfdacd57c79b79a03c7ca88f706ad9fb7b46831c1, fdacd57c79b79a03c7ca88f706ad9fb7b46831c1, fdacd57c79b79a03c7ca88f706ad9fb7b46831c1
LinuxLinux5.15, 0, 5.15.165
LinuxLinux6.11, fdacd57c79b79a03c7ca88f706ad9fb7b46831c1, fdacd57c79b79a03c7ca88f706ad9fb7b46831c1
linuxlinux_kernel5.15, 5.15, 5.15

Timeline

  • Aug 17, 2024 CVE Published
  • Nov 3, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›