Skip to main content

Threats Tagged 'cve-2024-36886'

View all threats tagged with 'cve-2024-36886'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-36886

Threats Tagged 'cve-2024-36886'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat has released a security update for the kpatch live patch modules targeting kernel version 4.18.0-305.120.1.el8_4. This update addresses two vulnerabilities: a use-after-free remote code execution flaw in TIPC message reassembly (CVE-2024-36886) and an out-of-bounds array indexing issue in the mac80211 WiFi subsystem (CVE-2024-41071). The update requires a system reboot to take effect and is rated with an Important security impact by Red Hat.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: x86/xen: Add some null pointer checking to smp.c (CVE-2024-26908) * kernel: TIPC message reassembly use-after-free remote code execution vulnerability (CVE-2024-36886) * kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() (CVE-2024-26993) * kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing (CVE-2024-41071) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: TIPC message reassembly use-after-free remote code execution vulnerability (CVE-2024-36886) * kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() (CVE-2024-26993) * kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing (CVE-2024-41071) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

A security update for the Red Hat Enterprise Linux kernel live patch module kpatch-patch-5_14_0-70_85_1 addresses multiple vulnerabilities including use-after-free issues and denial of service conditions. The update targets kernel version 5.14.0-70.85.1.el9_0 and fixes four CVEs related to kernel message reassembly, network route management, and virtio-net components. The update requires a system reboot to take effect.

Join the discussion

Red Hat has released a security update for the kpatch-patch-4_18_0-553 kernel live patch module targeting Red Hat Enterprise Linux 8. This update addresses two use-after-free vulnerabilities in the kernel: CVE-2024-36886 affecting TIPC message reassembly and CVE-2024-36971 affecting network route management. These vulnerabilities could potentially allow remote code execution or other impacts related to memory corruption. The update is rated as Important by Red Hat and is available for multiple architectures including x86_64 and ppc64le. Users of affected Red Hat Enterprise Linux 8 versions should apply the update to mitigate these issues.

Join the discussion

This advisory addresses two use-after-free vulnerabilities in the Linux kernel targeted by the kpatch live patch module for Red Hat Enterprise Linux 8.8. The vulnerabilities include CVE-2024-36886, affecting TIPC message reassembly, and CVE-2024-36971, affecting network route management. These flaws could potentially allow remote code execution or other impacts related to memory corruption. Red Hat has released an important security update patching these issues for kernel version 4.18.0-477.43.1.el8_8. The update is available as a kpatch live patch module, enabling modification of running kernel code without reboot. No known exploits are reported in the wild at this time.

Join the discussion
0

A use-after-free vulnerability (CVE-2024-36886) exists in the TIPC message reassembly code of the Linux kernel, which is addressed by a kpatch live patch module update for Red Hat Enterprise Linux 9. This vulnerability could allow remote code execution. Red Hat has released an important security update for the kpatch-patch module to fix this issue. The update requires a system reboot to take effect. The affected products include multiple variants and update streams of Red Hat Enterprise Linux 9 for x86_64 and ppc64le architectures.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cve-2024-36886
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses