CVE Database
/

CVE-2024-27395

Back to search

CVE-2024-27395

Published: May 9, 2024

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit Since kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal of ovs_ct_limit_exit, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.

VendorProductVersions

Linux

Linux

affected
11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 2db9a8c0a01fa1c762c1e61a13c212c492752994
affected
11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 589523cf0b384164e445dd5db8d5b1bf97982424
affected
11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 35880c3fa6f8fe281a19975d2992644588ca33d3
affected
11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 9048616553c65e750d43846f225843ed745ec0d4
affected
11efd5cb04a184eea4f57b68ea63dddd463158d1 - < bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1

+3 more versions

Linux

Linux

affected
4.18
unaffected
0 - < 4.18
unaffected
4.19.313 - <= 4.19.*
unaffected
5.4.275 - <= 5.4.*
unaffected
5.10.216 - <= 5.10.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now