Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35969

18
FAUCET Score

CVE-2024-35969 is a race condition vulnerability in the Linux kernel's IPv6 networking stack, specifically affecting the ipv6_get_ifaddr and ipv6_del_addr functions. This flaw can lead to a use-after-free condition due to incorrect handling of reference counts for IPv6 address entries, impacting Debian Linux and other Linux kernel versions. Rated as Medium severity (CVSS 5.5), the vulnerability has a local attack vector and low attack complexity, potentially resulting in a denial-of-service (DoS) due to system crashes. The CWE-770 classification indicates a missing protection mechanism against an allocation of excessive resources. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.35, < 4.19.313CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.275CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.216CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.156CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.87CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 71st percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-372.111.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: kernel-0:4.18.0-477.74.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.31.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: kernel-0:5.14.0-284.73.1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-372.111.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: kernel-rt-0:5.14.0-284.73.1.rt14.358.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-372.111.1.el8_6
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel

Vendor Advisories (3)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2024-35969Moderate

kernel: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr

May 20, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-613116.html
git.kernel.org / stable/c/01b11a0566670612bd464a932e5ac2eae53d8652
Patch
git.kernel.org / stable/c/3fb02ec57ead2891a2306af8c51a306bc5945e70
Patch
git.kernel.org / stable/c/4b19e9507c275de0cfe61c24db69179dc52cf9fb
Patch
git.kernel.org / stable/c/6cdb20c342cd0193d3e956e3d83981d0f438bb83
Patch
git.kernel.org / stable/c/7633c4da919ad51164acbf1aa322cc1a3ead6129
Patch
git.kernel.org / stable/c/b4b3b69a19016d4e7fbdbd1dbcc184915eb862e1
Patch
git.kernel.org / stable/c/cca606e14264098cba65efa82790825dbf69e903
Patch
git.kernel.org / stable/c/de76ae9ea1a6cf9e77fcec4f2df2904e26c23ceb
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2024/06/msg00020.html
Mailing ListThird Party Advisory