CVE-2024-56751
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-56751 is a vulnerability affecting the Linux kernel that stems from the improper handling of nexthops during device removal in IPv6. The issue causes the system to hang up during device removal in the pmtu.sh self-test, leading to instability. The root cause was identified as a fib6\_info entry that held a reference to the affected device. To mitigate the issue, the fib6\_info cleanup has been moved to ip6\_dst\_ifdown() to ensure proper release of the nexthop when disconnecting a device from a live IPv6 destination. The vulnerability was observed to cause a spat (system crash) every ten iterations during testing on an unpatched kernel.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.