CVE-2024-27016

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27016
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27016.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-27016
Downstream
Related
Published
2024-05-01T05:29:57.099Z
Modified
2025-11-28T02:35:36.949775Z
Summary
netfilter: flowtable: validate pppoe header
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: validate pppoe header

Ensure there is sufficient room to access the protocol field of the PPPoe header. Validate it once before the flowtable lookup, then use a helper function to access protocol field.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27016.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
72efd585f7144a047f7da63864284764596ccad9
Fixed
d06977b9a4109f8738bb276125eb6a0b772bc433
Fixed
8bf7c76a2a207ca2b4cfda0a279192adf27678d7
Fixed
a2471d271042ea18e8a6babc132a8716bb2f08b9
Fixed
cf366ee3bc1b7d1c76a882640ba3b3f8f1039163
Fixed
87b3593bed1868b2d9fe096c01bcdf0ea86cbebf

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.157
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.88
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.29
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.8