CVE-2024-35897: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: discard table flag update with pending basechain deletion Hook unregistration is deferred to the commit phase, same occurs with hook updates triggered by the table dormant flag. When both commands are combined, this results in deleting a basechain while leaving its hook still registered in the core.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 5.4.262, before 5.4.274 (fixed in 5.4.274); from 5.10.202, before 5.10.215 (fixed in 5.10.215); from 5.13.1, before 5.15.155 (fixed in 5.15.155); from 5.16, before 6.1.86 (fixed in 6.1.86); from 6.2, before 6.6.26 (fixed in 6.6.26); from 6.7, before 6.8.5 (fixed in 6.8.5); …
Published 2024-05-19. Last modified 2026-08-04.