Review reviewHigh

CVE-2024-27020

Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() nft_unregister_expr() can concurrent with __nft_expr_type_get(), and there is not any protection when iterate over nf_tables_expressions list in __nft_expr_type_get(). Therefore, there is potential data-race of nf_tables_expressions list entry. Use list_for_each_entry_rcu() to iterate over nf_tables_expressions list in __nft_expr_type_get(), and use rcu_read_lock() in the caller nft_expr_type_get() to protect the entire type query process.

CVSS
7
EPSS
0.22%
12.5% percentile
CISA KEV
Not listed
Published
2024.05.01
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.22%
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() nft_unregister_expr() can concurrent with __nft_expr_type_get(), and there is not any protection when iterate over nf_tables_expressions list in __nft_expr_type_get(). Therefore, there is potential data-race of nf_tables_expressions list entry. Use list_for_each_entry_rcu() to iterate over nf_tables_expressions list in __nft_expr_type_get(), and use rcu_read_lock() in the caller nft_expr_type_get() to protect the entire type query process.

Affected product and versions

Product
Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family
Affected versions
>= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < 939109c0a8e2a006a6cc8209e262d25065f4403a, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < b38a133d37fa421c8447b383d788c9cc6f5cb34c, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < 934e66e231cff2b18faa2c8aad0b8cec13957e05, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < 0b6de00206adbbfc6373b3ae38d2a6f197987907, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < 8d56bad42ac4c43c6c72ddd6a654a2628bf839c5, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < a9ebf340d123ae12582210407f879d6a5a1bc25b, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < 01f1a678b05ade4b1248019c2dcca773aebbeb7f, >= ef1f7df9170dbd875ce198ba84e6ab80f6fc139e < f969eb84ce482331a991079ab7a5c4dc3b7f89bf, >= 3.13, < V3.1, >= V3.1.0 < V3.1.5, >= 3.13 < 4.19.313, >= 4.20 < 5.4.275, >= 5.5 < 5.10.216, >= 5.11 < 5.15.157, >= 5.16 < 6.1.88, >= 6.2 < 6.6.29, >= 6.7 < 6.8.8, 6.9
Fixed versions
4.19.313, 5.4.275, 5.10.216, 5.15.157, 6.1.88, 6.6.29, 6.8.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-362