Review reviewHigh

CVE-2024-44987

Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reported an UAF in ip6_send_skb() [1] After ip6_local_out() has returned, we no longer can safely dereference rt, unless we hold rcu_read_lock(). A similar issue has been fixed in commit a688caa34beb ("ipv6: take rcu lock in rawv6_send_hdrinc()") Another potential issue in ip6_finish_output2() is handled in a separate patch. [1] BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964 Read of size 8 at addr ffff88806dde4858 by task syz.1.380/6530 CPU:...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.09.05
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reported an UAF in ip6_send_skb() [1] After ip6_local_out() has returned, we no longer can safely dereference rt, unless we hold rcu_read_lock(). A similar issue has been fixed in commit a688caa34beb ("ipv6: take rcu lock in rawv6_send_hdrinc()") Another potential issue in ip6_finish_output2() is handled in a separate patch. [1] BUG: KASAN: slab-use-after-free in ip6_send_skb+0x18d/0x230 net/ipv6/ip6_output.c:1964 Read of size 8 at addr ffff88806dde4858 by task syz.1.380/6530 CPU:...

Affected product and versions

Product
Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family
Affected versions
>= 0625491493d9000e4556bf566d205c28c8e7dc4e < 571567e0277008459750f0728f246086b2659429, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < ce2f6cfab2c637d0bd9762104023a15d0ab7c0a8, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < cb5880a0de12c7f618d2bdd84e2d985f1e06ed7e, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < 24e93695b1239fbe4c31e224372be77f82dab69a, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < 9a3e55afa95ed4ac9eda112d4f918af645d72f25, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < af1dde074ee2ed7dd5bdca4e7e8ba17f44e7b011, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < e44bd76dd072756e674f45c5be00153f4ded68b2, >= 0625491493d9000e4556bf566d205c28c8e7dc4e < faa389b2fbaaec7fd27a390b4896139f9da662e3, >= 2.6.32, < V3.2, < V3.1, >= 2.6.32 < 4.19.321, >= 4.20 < 5.4.283, >= 5.5 < 5.10.225, >= 5.11 < 5.15.166, >= 5.16 < 6.1.107, >= 6.2 < 6.6.48, >= 6.7 < 6.10.7, 6.11
Fixed versions
4.19.321, 5.4.283, 5.10.225, 5.15.166, 6.1.107, 6.6.48, 6.10.7

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-44987 — Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family | SECUFOCUS NOW