ipv6: sr: fix invalid unregister error path

Summary

CVECVE-2024-38612
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-06-19 14:15:21 UTC
Updated2026-05-12 12:16:55 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregister_family() isn't called. This issue exist since commit 46738b1317e1 ("ipv6: sr: add option to control lwtunnel support"), and commit 5559cea2d5aa ("ipv6: sr: fix possible use-after-free and null-ptr-deref") replaced unregister_pernet_subsys() with genl_unregister_family() in this error path.

Risk And Classification

Primary CVSS: v3.1 9.8 CRITICAL from ADP

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem Types: CWE-416 | CWE-476 | CWE-476 CWE-476 NULL Pointer Dereference | CWE-416 CWE-416 Use After Free


VersionSourceTypeScoreSeverityVector
3.1ADPDECLARED9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1134c704f-9b21-4f2e-91b3-4a467353bcc0Secondary9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 10610575a3ac2a702bf5c57aa931beaf847949c7 git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 646cd236c55e2cb5f146fc41bbe4034c4af5b2a4 git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 00e6335329f23ac6cf3105931691674e28bc598c git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 1a63730fb315bb1bab97edd69ff58ad45e04bb01 git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d e77a3ec7ada84543e75722a1283785a6544de925 git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 3398a40dccb88d3a7eef378247a023a78472db66 git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 85a70ff1e572160f1eeb096ed48d09a1c9d4d89a git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d c04d6a914e890ccea4a9d11233009a2ee7978bf4 git Not specified
CNA Linux Linux affected 46738b1317e169b281ad74690276916e24d1be6d 160e9d2752181fcf18c662e74022d77d3164cd45 git Not specified
CNA Linux Linux affected 4.10 Not specified
CNA Linux Linux unaffected 4.10 semver Not specified
CNA Linux Linux unaffected 4.19.316 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.278 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.219 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.161 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.93 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.33 6.6.* semver Not specified
CNA Linux Linux unaffected 6.8.12 6.8.* semver Not specified
CNA Linux Linux unaffected 6.9.3 6.9.* semver Not specified
CNA Linux Linux unaffected 6.10 * original_commit_for_fix Not specified
ADP Linux Linux Kernel affected 46738b1317e1 0610575a3ac custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 646cd236c55e custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 00e6335329f2 custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 1a63730fb315 custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 e77a3ec7ada8 custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 3398a40dccb8 custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 85a70ff1e572 custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 c04d6a914e89 custom Not specified
ADP Linux Linux Kernel affected 46738b1317e1 160e9d275218 custom Not specified
ADP Linux Linux Kernel affected 4.10 Not specified
ADP Linux Linux Kernel unaffected 4.10 custom Not specified
ADP Linux Linux Kernel unaffected 4.19.316 4.20 custom Not specified
ADP Linux Linux Kernel unaffected 5.4.278 5.5 custom Not specified
ADP Linux Acrn unaffected 5.10.219 5.11 custom Not specified
ADP Linux Linux Kernel unaffected 5.15.161 5.16 custom Not specified
ADP Linux Linux Kernel unaffected 6.1.93 6.2 custom Not specified
ADP Linux Linux Kernel unaffected 6.6.33 6.7 custom Not specified
ADP Linux Linux Kernel unaffected 6.8.12 6.9 custom Not specified
ADP Linux Linux Kernel unaffected 6.9.3 6.10 custom Not specified
ADP Linux Linux Kernel unaffected 6.10-rc1 Not specified
ADP Siemens RUGGEDCOM RST2428P affected V3.1 custom Not specified
ADP Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 Family unaffected * custom Not specified
ADP Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 Family affected V3.1 custom Not specified
ADP Siemens SIMATIC S7-1500 TM MFP - GNU/Linux Subsystem affected * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.0 V3.1.5 custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.0 V3.1.5 custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP affected V3.1.0 V3.1.5 custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP affected V3.1.0 V3.1.5 custom Not specified
ADP Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.0 V3.1.5 custom Not specified

References

ReferenceSourceLinkTags
cert-portal.siemens.com/productcert/html/ssa-398330.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/1a63730fb315bb1bab97edd69ff58ad45e04bb01 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/c04d6a914e890ccea4a9d11233009a2ee7978bf4 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/85a70ff1e572160f1eeb096ed48d09a1c9d4d89a af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
cert-portal.siemens.com/productcert/html/ssa-265688.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/160e9d2752181fcf18c662e74022d77d3164cd45 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/e77a3ec7ada84543e75722a1283785a6544de925 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/00e6335329f23ac6cf3105931691674e28bc598c af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/646cd236c55e2cb5f146fc41bbe4034c4af5b2a4 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/3398a40dccb88d3a7eef378247a023a78472db66 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
cert-portal.siemens.com/productcert/html/ssa-613116.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
lists.debian.org/debian-lts-announce/2024/06/msg00020.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org
git.kernel.org/stable/c/10610575a3ac2a702bf5c57aa931beaf847949c7 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report