CVE-2024-27417

Source
https://cve.org/CVERecord?id=CVE-2024-27417
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27417.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-27417
Downstream
Related
Published
2024-05-17T11:51:07.803Z
Modified
2026-05-28T03:52:58.686914023Z
Summary
ipv6: fix potential "struct net" leak in inet6_rtm_getaddr()
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix potential "struct net" leak in inet6rtmgetaddr()

It seems that if userspace provides a correct IFATARGETNETNSID value but no IFAADDRESS and IFALOCAL attributes, inet6rtmgetaddr() returns -EINVAL with an elevated "struct net" refcount.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27417.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6ecf4c37eb3e89b0832c9616089a5cdca3747da7
Fixed
9d4ffb5b9d879a75e4f7460e8b10e756b4dfb132
Fixed
810fa7d5e5202fcfb22720304b755f1bdfd4c174
Fixed
8a54834c03c30e549c33d5da0975f3e1454ec906
Fixed
1b0998fdd85776775d975d0024bca227597e836a
Fixed
44112bc5c74e64f28f5a9127dc34066c7a09bd0f
Fixed
33a1b6bfef6def2068c8703403759024ce17053e
Fixed
10bfd453da64a057bcfd1a49fb6b271c48653cdb

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27417.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.271
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.212
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.151
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.81
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.21
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27417.json"