Executive brief
A use-after-free vulnerability in the Linux kernel's networking component exists due to improper RCU rules in __dst_negative_advice(). The function fails to clear the destination cache before releasing it, potentially allowing for remote code execution or local privilege escalation.
Affected products
- Google Android OS
- Linux Linux Kernel 4.6 to 6.9.4
- Debian Debian Linux 10.0
Timeline
- 2024-06-01: disclosed: Initial patches appearing in kernel mailing lists/git.
- 2024-08-07: advisory: Vulnerability published and added to CISA KEV.
- 2024-08-07: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2024-08-07: exploited: Reported as exploited in the wild.