Database/Kernel, userspace & hypervisor
Linux kernel (net routing): Use-after-free in network route management (__dst_negative_advice) - actively exploited
CVSS 7.8CVE-2024-36971Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Use-after-free in network route management (__dst_negative_advice) - actively exploited [KEV]
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN
What to do
Livepatchable; otherwise drain + reboot
References
Related entries
- Microsoft Hyper-V: Hyper-V elevation of privilege, exploited in the wildCVE-2024-38080 · Microsoft Hyper-VHigh
- Linux kernel (drivers/gpu/drm): DRM core stores a pointer to the caller's struct pid before taking a reference on itCVE-2024-39486 · Linux kernel (drivers/gpu/drm)High
- Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the userCVE-2024-40990 · Linux kernel mlx5_ib (shared receive queue)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2024-41011 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel BPF: use-after-free freeing map elements that hold BPF timersCVE-2024-41045 · Linux kernel BPF timers (bpf_timer_cancel_and_free, hrtimer freed while still enqueued)High
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2024-41092 · Linux i915 GPU kernel driverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.