CVE-2024-39504: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: validate mandatory meta and payload Check for mandatory netlink attributes in payload and meta expression when used embedded from the inner expression, otherwise NULL pointer dereference is possible from userspace.

Affected products

  • Linux Linux Kernel: from 6.2, before 6.6.35 (fixed in 6.6.35); from 6.7, before 6.9.6 (fixed in 6.9.6); version 6.10 only

Published 2024-07-12. Last modified 2026-06-17.