CVE-2024-44983

Source
https://cve.org/CVERecord?id=CVE-2024-44983
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44983.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-44983
Downstream
Published
2024-09-04T19:54:32.830Z
Modified
2026-05-18T05:58:58.121267074Z
Summary
netfilter: flowtable: validate vlan header
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: validate vlan header

Ensure there is sufficient room to access the protocol field of the VLAN header, validate it once before the flowtable lookup.

===================================================== BUG: KMSAN: uninit-value in nfflowoffloadinethook+0x45a/0x5f0 net/netfilter/nfflowtableinet.c:32 nfflowoffloadinethook+0x45a/0x5f0 net/netfilter/nfflowtableinet.c:32 nfhookentryhookfn include/linux/netfilter.h:154 [inline] nfhookslow+0xf4/0x400 net/netfilter/core.c:626 nfhookingress include/linux/netfilternetdev.h:34 [inline] nf_ingress net/core/dev.c:5440 [inline]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/44xxx/CVE-2024-44983.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4cd91f7c290f64fe430867ddbae10bff34657b6a
Fixed
c05155cc455785916164aa5e1b4605a2ae946537
Fixed
d9384ae7aec46036d248d1c2c2757e471ab486c3
Fixed
0279c35d242d037abeb73d60d06a6d1bb7f672d9
Fixed
043a18bb6cf16adaa2f8642acfde6e8956a9caaa
Fixed
6ea14ccb60c8ab829349979b22b58a941ec4a3ee

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44983.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.166
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.107
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.48
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44983.json"