netfilter: nft_set_pipapo: walk over current view on netlink dump
Summary
| CVE | CVE-2024-27017 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-01 06:15:20 UTC |
| Updated | 2026-08-04 11:17:33 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view on netlink dump The generation mask can be updated while netlink dump is in progress. The pipapo set backend walk iterator cannot rely on it to infer what view of the datastructure is to be used. Add notation to specify if user wants to read/update the set. Based on patch from Florian Westphal. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Problem Types: NVD-CWE-noinfo
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Operating System | Fedoraproject | Fedora | 39 | All | All | All |
| Operating System | Fedoraproject | Fedora | 40 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | 6.9 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 6.9 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 6.9 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 6.9 | rc4 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 2a90da8e0dd50f42e577988f4219f4f4cd3616b7 ff89db14c63a827066446460e39226c0688ef786 git | Not specified |
| CNA | Linux | Linux | affected 45eb6944d0f55102229115de040ef3a48841434a ce9fef54c5ec9912a0c9a47bac3195cc41b14679 git | Not specified |
| CNA | Linux | Linux | affected 0d836f917520300a8725a5dbdad4406438d0cead 52735a010f37580b3a569a996f878fdd87425650 git | Not specified |
| CNA | Linux | Linux | affected 2b84e215f87443c74ac0aa7f76bb172d43a87033 f24d8abc2bb8cbf31ec713336e402eafa8f42f60 git | Not specified |
| CNA | Linux | Linux | affected 2b84e215f87443c74ac0aa7f76bb172d43a87033 721715655c72640567e8742567520c99801148ed git | Not specified |
| CNA | Linux | Linux | affected 2b84e215f87443c74ac0aa7f76bb172d43a87033 29b359cf6d95fd60730533f7f10464e95bd17c73 git | Not specified |
| CNA | Linux | Linux | affected f661383b5f1aaac3fe121b91e04332944bc90193 git | Not specified |
| CNA | Linux | Linux | affected 5.10.186 5.10.227 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.119 5.15.168 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.36 6.1.112 semver | Not specified |
| CNA | Linux | Linux | affected 6.3.10 6.4 semver | Not specified |
| CNA | Linux | Linux | affected 6.4 | Not specified |
| CNA | Linux | Linux | unaffected 6.4 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.227 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.168 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.112 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.53 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.8.8 6.8.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.9 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/29b359cf6d95fd60730533f7f10464e95bd17c73 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/ce9fef54c5ec9912a0c9a47bac3195cc41b14679 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| lists.debian.org/debian-lts-announce/2025/03/msg00002.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| git.kernel.org/stable/c/52735a010f37580b3a569a996f878fdd87425650 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| git.kernel.org/stable/c/721715655c72640567e8742567520c99801148ed | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f24d8abc2bb8cbf31ec713336e402eafa8f42f60 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| lists.debian.org/debian-lts-announce/2025/01/msg00001.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| git.kernel.org/stable/c/ff89db14c63a827066446460e39226c0688ef786 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.