In the Linux kernel, the following vulnerability has been resolved:
net: mctp: take ownership of skb in mctp_local_output
Currently, mctp_local_output only takes ownership of skb on success, and
we may leak an skb if mctp_local_output fails in specific states; the
skb ownership isn't transferred until the actual output routing occurs.
Instead, make mctp_local_output free the skb on all error paths up to
the route action, so it always consumes the passed skb.
References
Configurations
Configuration 1 (hide)
|
History
26 Sep 2025, 16:22
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
First Time |
Linux linux Kernel
Linux |
|
CWE | CWE-401 | |
References | () https://git.kernel.org/stable/c/3773d65ae5154ed7df404b050fd7387a36ab5ef3 - Patch | |
References | () https://git.kernel.org/stable/c/a3c8fa54e904b0ddb52a08cc2d8ac239054f61fd - Patch | |
References | () https://git.kernel.org/stable/c/a639441c880ac479495e5ab37e3c29f21ae5771b - Patch | |
References | () https://git.kernel.org/stable/c/cbebc55ceacef1fc0651e80e0103cc184552fc68 - Patch | |
CPE | cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:* |
21 Nov 2024, 09:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://git.kernel.org/stable/c/3773d65ae5154ed7df404b050fd7387a36ab5ef3 - | |
References | () https://git.kernel.org/stable/c/a3c8fa54e904b0ddb52a08cc2d8ac239054f61fd - | |
References | () https://git.kernel.org/stable/c/a639441c880ac479495e5ab37e3c29f21ae5771b - | |
References | () https://git.kernel.org/stable/c/cbebc55ceacef1fc0651e80e0103cc184552fc68 - | |
Summary |
|
17 May 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-17 12:15
Updated : 2025-09-26 16:22
NVD link : CVE-2024-27418
Mitre link : CVE-2024-27418
CVE.ORG link : CVE-2024-27418
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-401
Missing Release of Memory after Effective Lifetime