Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-36886

9.8 · CRITICAL
Published May 30, 2024 linux CWE-416 EPSS 1.31% (68th pctl)

Overview

CVE-2024-36886 is a critical-severity vulnerability affecting linux linux_kernel. It was published on May 30, 2024 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix UAF in error path

Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported

a UAF in the tipc_buf_append() error path:

BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0

linux/net/core/skbuff.c:1183

Read of size 8 at addr ffff88804d2a7c80 by task poc/8034

CPU: 1 PID: 8034 Comm: poc Not tainted 6.8.2 #1

Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS

1.16.0-debian-1.16.0-5 04/01/2014

Call Trace:

<IRQ>

__dump_stack linux/lib/dump_stack.c:88

dump_stack_lvl+0xd9/0x1b0 linux/lib/dump_stack.c:106

print_address_description linux/mm/kasan/report.c:377

print_report+0xc4/0x620 linux/mm/kasan/report.c:488

kasan_report+0xda/0x110 linux/mm/kasan/report.c:601

kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183

skb_release_data+0x5af/0x880 linux/net/core/skbuff.c:1026

skb_release_all linux/net/core/skbuff.c:1094

__kfree_skb linux/net/core/skbuff.c:1108

kfr

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.1, < 4.19.314 Affected

Frequently Asked Questions

What is CVE-2024-36886?

CVE-2024-36886 is a critical-severity vulnerability affecting linux linux_kernel. It was published on May 30, 2024 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

How severe is CVE-2024-36886?

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-36886?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-36886?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-36886 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.