CVE-2024-26735: ipv6: sr: fix possible use-after-free and null-ptr-deref

Description

In the Linux kernel, the following vulnerability has been resolved:

ipv6: sr: fix possible use-after-free and null-ptr-deref

The pernet operations structure for the subsystem must be registered
before registering the generic netlink family.

Classification

CVE ID: CVE-2024-26735

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 15.26% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/953f42934533c151f440cd32390044d2396b87aa
https://git.kernel.org/stable/c/82831e3ff76ef09fb184eb93b79a3eb3fb284f1d
https://git.kernel.org/stable/c/65c38f23d10ff79feea1e5d50b76dc7af383c1e6
https://git.kernel.org/stable/c/91b020aaa1e59bfb669d34c968e3db3d5416bcee
https://git.kernel.org/stable/c/8391b9b651cfdf80ab0f1dc4a489f9d67386e197
https://git.kernel.org/stable/c/9e02973dbc6a91e40aa4f5d87b8c47446fbfce44
https://git.kernel.org/stable/c/02b08db594e8218cfbc0e4680d4331b457968a9b
https://git.kernel.org/stable/c/5559cea2d5aa3018a5f00dd2aca3427ba09b386b

Timeline