CVE-2024-36484 is a medium-severity vulnerability in the Linux kernel's networking subsystem, specifically affecting the handling of socket states during the accept system call. This flaw can lead to a denial of service (DoS) due to a kernel warning, triggered when a socket enters the FIN_WAIT1 state before being accepted. The vulnerability impacts Linux kernel versions and is rated with a CVSS score of 5.5. The attack vector is local, requiring low privileges and low attack complexity. A successful exploit could result in high availability impact, causing system instability or crashes. There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.19.314, < 4.19.319CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.4.276, < 5.4.281CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.10.217, < 5.10.223CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.159, < 5.15.164CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1.91, < 6.1.93CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.