CVE-2024-27395
Published: May 9, 2024
Modified: May 12, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit Since kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal of ovs_ct_limit_exit, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 2db9a8c0a01fa1c762c1e61a13c212c492752994affected 11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 589523cf0b384164e445dd5db8d5b1bf97982424affected 11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 35880c3fa6f8fe281a19975d2992644588ca33d3affected 11efd5cb04a184eea4f57b68ea63dddd463158d1 - < 9048616553c65e750d43846f225843ed745ec0d4affected 11efd5cb04a184eea4f57b68ea63dddd463158d1 - < bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1+3 more versions |
Linux | Linux | affected 4.18unaffected 0 - < 4.18unaffected 4.19.313 - <= 4.19.*unaffected 5.4.275 - <= 5.4.*unaffected 5.10.216 - <= 5.10.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now