Review reviewHigh

CVE-2024-35899

Linux Linux, linux_kernel, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: flush pending destroy work before exit_net release Similar to 2c9f0293280e ("netfilter: nf_tables: flush pending destroy work before netlink notifier") to address a race between exit_net and the destroy workqueue. The trace below shows an element to be released via destroy workqueue while exit_net path (triggered via module removal) has already released the set that is used in such transaction. [ 1360.547789] BUG: KASAN: slab-use-after-free in nf_tables_trans_destroy_work+0x3f5/0x590 [nf_tables] [ 1360...

CVSS
7.3
EPSS
0.20%
9.93% percentile
CISA KEV
Not listed
Published
2024.05.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.20%
Technical severityCVSS 7.3

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: flush pending destroy work before exit_net release Similar to 2c9f0293280e ("netfilter: nf_tables: flush pending destroy work before netlink notifier") to address a race between exit_net and the destroy workqueue. The trace below shows an element to be released via destroy workqueue while exit_net path (triggered via module removal) has already released the set that is used in such transaction. [ 1360.547789] BUG: KASAN: slab-use-after-free in nf_tables_trans_destroy_work+0x3f5/0x590 [nf_tables] [ 1360...

Affected product and versions

Product
Linux Linux, linux_kernel, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
Affected versions
>= 0935d558840099b3679c67bb7468dc78fcbad940 < f4e14695fe805eb0f0cb36e0ad6a560b9f985e86, >= 0935d558840099b3679c67bb7468dc78fcbad940 < 46c4481938e2ca62343b16ea83ab28f4c1733d31, >= 0935d558840099b3679c67bb7468dc78fcbad940 < f7e3c88cc2a977c2b9a8aa52c1ce689e7b394e49, >= 0935d558840099b3679c67bb7468dc78fcbad940 < 4e8447a9a3d367b5065a0b7abe101da6e0037b6e, >= 0935d558840099b3679c67bb7468dc78fcbad940 < 333b5085522cf1898d5a0d92616046b414f631a7, >= 0935d558840099b3679c67bb7468dc78fcbad940 < d2c9eb19fc3b11caebafde4c30a76a49203d18a6, >= 0935d558840099b3679c67bb7468dc78fcbad940 < 24cea9677025e0de419989ecb692acd4bb34cac2, >= 4.20, >= 0935d5588400 < f4e14695fe80, >= 0935d5588400 < 46c4481938e2, >= 0935d5588400 < f7e3c88cc2a9, >= 0935d5588400 < 4e8447a9a3d3, >= 0935d5588400 < 333b5085522c, >= 0935d5588400 < d2c9eb19fc3b, >= 0935d5588400 < 24cea9677025, >= 4.20 < 5.4.274, >= 5.5 < 5.10.215, >= 5.11 < 5.15.154, >= 5.16 < 6.1.85, >= 6.2 < 6.6.26
Fixed versions
5.4.274, 5.10.215, 5.15.154, 6.1.85, 6.6.26, 6.8.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux_kernel, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-362
CVE-2024-35899 — Linux Linux, linux_kernel, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem | SECUFOCUS NOW