CVE-2024-44986 - CVE House
Back to Database
Status published Unknown CVE-2024-44986

ipv6: fix possible UAF in ip6_finish_output2()

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to make sure the dst and associated idev are alive.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-44986

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
5796015fa968a3349027a27dcd04c71d95c53ba5, ded37d03440d0ab346a8287cc2ba88b8dc90ceb0, 2323690eb05865a657709f4d28eb9538ea97bfc2, b34c668a867ffdcf8bd8db4a36512572e82b4a15, 5.4.137, 5.10.55, 5.13.7, 5.14, 0, 5.15.166, 6.1.107, 6.6.48, 6.10.7, 6.11

Timeline

Official Publish: September 4th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.