In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent possible UAF in ip6_xmit()
If skbexpandhead() returns NULL, skb has been freed and the associated dst/idev could also have been freed.
We must use rcureadlock() to prevent a possible UAF.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/44xxx/CVE-2024-44985.json"
}[
{
"signature_version": "v1",
"digest": {
"length": 2004.0,
"function_hash": "13213428196257317996138500698640222955"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2024-44985-c96a9d1b",
"target": {
"function": "ip6_xmit",
"file": "net/ipv6/ip6_output.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c47e022011719fc5727bca661d662303180535ba"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"53458417411036856138282181531635571419",
"7891445641594684130530665419644758138",
"69890119548043594470274969445948151737",
"176531933359355517637259134920000171582",
"289145317399674226154485350328782261494",
"15253652675921018726110052793828364225",
"234417572947199921494995913766542411272",
"6808485886626584458785948596939744221",
"267546462884765554161030880927979632545"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2024-44985-cecf58eb",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c47e022011719fc5727bca661d662303180535ba"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-44985.json"