CVE-2024-36017: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation Each attribute inside a nested IFLA_VF_VLAN_LIST is assumed to be a struct ifla_vf_vlan_info so the size of such attribute needs to be at least of sizeof(struct ifla_vf_vlan_info) which is 14 bytes. The current size validation in do_setvfinfo is against NLA_HDRLEN (4 bytes) which is less than sizeof(struct ifla_vf_vlan_info) so this validation is not enough and a too small attribute might be cast to a struct ifla_vf_vlan_info, this might result in an out of bands read access when accessing the saved (casted) entry in ivvl.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.9, before 4.19.314 (fixed in 4.19.314); from 4.20, before 5.4.276 (fixed in 5.4.276); from 5.5, before 5.10.217 (fixed in 5.10.217); from 5.11, before 5.15.159 (fixed in 5.15.159); from 5.16, before 6.1.91 (fixed in 6.1.91); from 6.2, before 6.6.31 (fixed in 6.6.31); …

Published 2024-05-30. Last modified 2026-06-17.