CVE-2024-36031 is a critical vulnerability in the Linux kernel's key management system, specifically affecting the handling of key expiration during instantiation. This flaw causes keys, particularly those used for DNS resolution, to become permanent by overwriting their intended expiration time, thereby disabling future updates. Rated with a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector with low attack complexity, allowing an unauthenticated attacker to achieve high impact on confidentiality, integrity, and availability. The CWE is CWE-324 (Use of a Key with Insufficient Randomness), and it has a FAUCET Risk Score of 92/100. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Despite the lack of active exploits, the vulnerability has garnered significant community attention with 10 mentions, indicating awareness and discussion among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.206, < 5.10.217CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.146, < 5.15.159CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1.70, < 6.1.91CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.6.9, < 6.6.31CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.8.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.