CVE-2024-27403

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: reset dst in route object after setting up flow dst is transferred to the flow object, route object does not own it anymore. Reset dst in route object, otherwise if flow_offload_add() fails, error path releases dst twice, leading to a refcount underflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*

History

18 Sep 2025, 17:28

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4 - () https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4 - Patch
References () https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c - () https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c - Patch
References () https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148 - () https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148 - Patch
References () https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae - () https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae - Patch
References () https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3 - () https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3 - Patch
CWE NVD-CWE-Other

21 Nov 2024, 09:04

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: netfilter: nft_flow_offload: restablece dst en el objeto de ruta después de configurar el flujo dst se transfiere al objeto de flujo, el objeto de ruta ya no es propietario. Restablezca el dst en el objeto de ruta; de lo contrario, si flow_offload_add() fallo, la ruta de error libera el dst dos veces, lo que provoca un desbordamiento insuficiente del recuento.
References () https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4 - () https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4 -
References () https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c - () https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c -
References () https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148 - () https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148 -
References () https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae - () https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae -
References () https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3 - () https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3 -

17 May 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 12:15

Updated : 2025-09-18 17:28


NVD link : CVE-2024-27403

Mitre link : CVE-2024-27403

CVE.ORG link : CVE-2024-27403


JSON object : View

Products Affected

linux

  • linux_kernel