Executive Summary

Informations
Name CVE-2024-42154 First vendor Publication 2024-07-30
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Overall CVSS Score 4.4
Base Score 4.4 Environmental Score 4.4
impact SubScore 2.5 Temporal Score 4.4
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact Low
Integrity Impact Low Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

tcp_metrics: validate source addr length

I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least 4 bytes long, and the policy doesn't have an entry for this attribute at all (neither does it for IPv6 but v6 is manually validated).

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42154

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-754 Improper Check for Unusual or Exceptional Conditions

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3641

Sources (Detail)

http://www.openwall.com/lists/oss-security/2024/09/24/3
http://www.openwall.com/lists/oss-security/2024/09/24/4
http://www.openwall.com/lists/oss-security/2024/09/25/3
https://git.kernel.org/stable/c/19d997b59fa1fd7a02e770ee0881c0652b9c32c9
https://git.kernel.org/stable/c/2a2e79dbe2236a1289412d2044994f7ab419b44c
https://git.kernel.org/stable/c/31f03bb04146c1c6df6c03e9f45401f5f5a985d3
https://git.kernel.org/stable/c/3d550dd5418729a6e77fe7721d27adea7152e321
https://git.kernel.org/stable/c/66be40e622e177316ae81717aa30057ba9e61dff
https://git.kernel.org/stable/c/8c2debdd170e395934ac0e039748576dfde14e99
https://git.kernel.org/stable/c/cdffc358717e436bb67122bb82c1a2a26e050f98
https://git.kernel.org/stable/c/ef7c428b425beeb52b894e16f1c4b629d6cebfb6
https://security.netapp.com/advisory/ntap-20240828-0010/
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
Date Informations
2025-01-08 03:04:09
  • Multiple Updates
2025-01-07 03:03:42
  • Multiple Updates
2024-12-25 03:02:20
  • Multiple Updates
2024-12-12 03:05:16
  • Multiple Updates
2024-11-25 09:23:17
  • Multiple Updates
2024-11-22 21:22:31
  • Multiple Updates
2024-11-21 21:22:03
  • Multiple Updates
2024-11-20 02:58:52
  • Multiple Updates
2024-11-14 02:59:11
  • Multiple Updates
2024-11-09 02:59:11
  • Multiple Updates
2024-10-26 02:56:35
  • Multiple Updates
2024-10-25 02:58:30
  • Multiple Updates
2024-10-23 02:57:42
  • Multiple Updates
2024-10-02 17:27:49
  • Multiple Updates
2024-10-02 00:28:02
  • Multiple Updates
2024-09-15 02:49:07
  • Multiple Updates
2024-09-12 02:48:39
  • Multiple Updates
2024-09-07 02:47:39
  • Multiple Updates
2024-09-06 02:46:48
  • Multiple Updates
2024-09-04 02:50:01
  • Multiple Updates
2024-08-22 02:47:53
  • Multiple Updates
2024-08-08 21:27:50
  • Multiple Updates
2024-07-30 17:27:23
  • Multiple Updates
2024-07-30 13:27:26
  • First insertion