Home/CVE/Android Kernel Remote Code Execution Vulnerability
CVE

CVE-2024-36971

Android Kernel Remote Code Execution Vulnerability

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk-dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk-sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order.

Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three -negative_advice() existing methods must perform the sk_dst_reset() themselves. Note the check against NULL dst is centralized in __dst_negative_advice(), there is no need to duplicate it in various callbacks. Many thanks to Clement Lecigne for tracking this issue.

This old bug became visible after the blamed commit, using UDP sockets.

HIGH · CVSS 7.8 ⚠ CISA KEV EPSS 0.00449
Act now
  • Listed on CISA KEV (known exploited in the wild)
  • SSVC exploitation status: active
  • CVSS base score ≥ 7.0
Sigma rules0 YARA rules0

Required Remediation

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness Classification

Affected Products & Versions

8
debian linuxall versions
linux kernel>= 4.6 and < 4.19.316
linux kernel>= 4.20 and < 5.4.278
linux kernel>= 5.5 and < 5.10.219
linux kernel>= 5.11 and < 5.15.161
linux kernel>= 5.16 and < 6.1.94
linux kernel>= 6.2 and < 6.6.34
linux kernel>= 6.7 and < 6.9.4

Scoring & Timeline

7.8
HIGH · CVSS v3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67
View on NVD
Attack Vector
Network Adjacent Local Physical
Attack Complexity
Low High
Privileges Required
None Low High
User Interaction
None Required
Scope
Unchanged Changed
Confidentiality
None Low High
Integrity
None Low High
Availability
None Low High
Published to NVD10 Jun 2024 · 09:15 AM
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC triage · cisa-vulnrichment
Exploitation
active
Automatable
no
Technical impact
total
SSVC asks the questions that actually drive patch urgency: is it being exploited, can attacks be automated, and how total is the impact.

Vendor Advisories

30
siemens-csafSSA-613116
suse-csafSUSE-SU-2025:20008-1
suse-csafSUSE-SU-2025:20028-1
suse-csafSUSE-SU-2025:0268-1
suse-csafSUSE-SU-2025:0242-1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin