CVE-2024-36031: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem for DNS resolution as the expiration set by user-space is overwritten to TIME64_MAX, disabling further DNS updates. Fix this by restoring the condition that key_set_expiry is only called when the pre-parser sets a specific expiry.

Affected products

  • Linux Linux Kernel: from 5.10.206, before 5.10.217 (fixed in 5.10.217); from 5.15.146, before 5.15.159 (fixed in 5.15.159); from 6.1.70, before 6.1.91 (fixed in 6.1.91); from 6.6.9, before 6.6.31 (fixed in 6.6.31); from 6.7, before 6.8.10 (fixed in 6.8.10); from 6.9, before 6.9.1 (fixed in 6.9.1)

Published 2024-05-30. Last modified 2026-06-17.