CVE-2024-36954: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, so move '*buf = NULL' after __skb_linearize(), so that the skb can be freed on the err path.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.4.271, before 4.5 (fixed in 4.5); from 4.9.271, before 4.10 (fixed in 4.10); from 4.14.235, before 4.15 (fixed in 4.15); from 4.19.193, before 4.19.314 (fixed in 4.19.314); from 5.4.124, before 5.4.276 (fixed in 5.4.276); from 5.10.42, before 5.10.217 (fixed in 5.10.217); …

Published 2024-05-30. Last modified 2026-06-17.