CVE-2024-36031 - CVE House
Back to Database
Status published Unknown CVE-2024-36031

keys: Fix overwrite of key expiration on instantiation

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem for DNS resolution as the expiration set by user-space is overwritten to TIME64_MAX, disabling further DNS updates. Fix this by restoring the condition that key_set_expiry is only called when the pre-parser sets a specific expiry.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-36031

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
97be1e865e70e5a0ad0a5b5f5dca5031ca0b53ac, 2552b32b0b349df160a509fe49f5f308cb922f2b, 791d5409cdb974c31a1bc7a903ea729ddc7d83df, afc360e8a1256acb7579a6f5b6f2c30b85b39301, 39299bdd2546688d92ed9db4948f6219ca1b9542, 5.10.206, 5.15.146, 6.1.70, 6.6.9, 6.7, 0, 5.10.217, 5.15.159, 6.1.91, 6.6.31, 6.8.10, 6.9.1, 6.10

Timeline

Official Publish: May 30th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.