CVE-2024-53141

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53141
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53141.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53141
Downstream
Related
Published
2024-12-06T09:37:02.009Z
Modified
2025-11-28T02:35:47.972903Z
Summary
netfilter: ipset: add missing range check in bitmap_ip_uadt
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: add missing range check in bitmapipuadt

When tb[IPSETATTRIPTO] is not present but tb[IPSETATTRCIDR] exists, the values of ip and ipto are slightly swapped. Therefore, the range check for ip should be done later, but this part is missing and it seems that the vulnerability occurs.

So we should add missing range checks and remove unnecessary range checks.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53141.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
72205fc68bd13109576aa6c4c12c740962d28a6c
Fixed
3c20b5948f119ae61ee35ad8584d666020c91581
Fixed
78b0f2028f1043227a8eb0c41944027fc6a04596
Fixed
2e151b8ca31607d14fddc4ad0f14da0893e1a7c7
Fixed
e67471437ae9083fa73fa67eee1573fec1b7c8cf
Fixed
7ffef5e5d5eeecd9687204a5ec2d863752aafb7e
Fixed
856023ef032d824309abd5c747241dffa33aae8c
Fixed
591efa494a1cf649f50a35def649c43ae984cd03
Fixed
15794835378ed56fb9bacc6a5dd3b9f33520604e
Fixed
35f56c554eb1b56b77b3cf197a6b00922d49033d

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.39
Fixed
4.19.325
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.287
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.231
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.174
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.120
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.64
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.11
Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.2