CVE-2024-38612·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregister_family() isn't called. This issue exist since commit 46738b1317e1 ("ipv6: sr: add option to control lwtunnel support"), and commit 5559cea2d5aa ("ipv6: sr: fix possible use-after-free and null-ptr-deref") replaced unregister_pernet_subsys() with genl_unregister_family() in this error path.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 6.9.3
- Published
- 2024-06-19
Affected versions
From: 6.9
Until: 6.9.3
Fixed in: 6.9.3
How to fix this CVE
Update your Linux kernel to version 6.9.3 or later to fix an error handling flaw in the IPv6 Segment Routing (SR) subsystem initialization. When CONFIG_IPV6_SEG6_LWTUNNEL is disabled and seg6_hmac_init() fails, the generic netlink family fails to unregister properly, leaving kernel resources in an inconsistent state. This patch ensures proper cleanup in all error paths regardless of compile-time configuration options.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version: uname -r — verify it is 6.9.3 or later
- Verify IPv6 SR configuration: cat /boot/config-$(uname -r) | grep -i seg6 — confirm if SEG6 modules are loaded or compiled in
- Check kernel module status: lsmod | grep seg6 — confirm if the vulnerable seg6 module is currently loaded
- Confirm the patch by checking kernel build date: uname -v — if built after the fix date (check kernel.org commit dates), you are patched
FAQ
What is CVE-2024-38612?
CVE-2024-38612 is a kernel resource cleanup vulnerability in the IPv6 Segment Routing (SR) subsystem where the error handling path fails to unregister the generic netlink family when certain initialization failures occur, potentially leaving kernel structures in an unrecoverable state.
Is CVE-2024-38612 being actively exploited?
No. CVE-2024-38612 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available.
What versions of Kernel are affected by CVE-2024-38612?
Linux kernel versions 6.9 through 6.9.3 are affected. The vulnerability was introduced in commit 46738b1317e1 and fixed in version 6.9.3.
How do I check if my server is vulnerable to CVE-2024-38612?
Run uname -r to check your kernel version; if it shows 6.9.0, 6.9.1, 6.9.2, or 6.9.3 (before the patch), your system may be vulnerable. Also verify if IPv6 SR is enabled: cat /boot/config-$(uname -r) | grep CONFIG_IPV6_SEG6.
Does Defensia detect CVE-2024-38612?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-38612 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/00e6335329f23ac6cf3105931691674e28bc598c
- https://git.kernel.org/stable/c/10610575a3ac2a702bf5c57aa931beaf847949c7
- https://git.kernel.org/stable/c/160e9d2752181fcf18c662e74022d77d3164cd45
- https://git.kernel.org/stable/c/1a63730fb315bb1bab97edd69ff58ad45e04bb01
- https://git.kernel.org/stable/c/3398a40dccb88d3a7eef378247a023a78472db66
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-38612. Free for 1 server.
Get started free