Vulnerability record · CVE-2024-36971 · published 10 June 2024
CVE-2024-36971: Linux kernel use-after-free in __dst_negative_advice()
Debian · Debian Linux
The Linux kernel's __dst_negative_advice() clears sk->dst_cache in the wrong order relative to dst_release(), violating RCU rules and allowing a use-after-free. The bug became reachable after a related change and is triggered via UDP sockets, making it a memory-corruption issue in core networking code.
Description
In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order. Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three ->negative_advice() existing methods must perform the sk_dst_reset() themselves. Note the check against NULL dst is centralized in __dst_negative_advice(), there is no need to duplicate it in various callbacks. Many thanks to Clement Lecigne for tracking this issue. This old bug became visible after the blamed commit, using UDP sockets.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a kernel use-after-free with high CVSS impact and confirmed inclusion in CISA KEV, though exploitation requires local access and the EPSS probability is modest.
What it is
The Linux kernel's __dst_negative_advice() clears sk->dst_cache in the wrong order relative to dst_release(), violating RCU rules and allowing a use-after-free. The bug became reachable after a related change and is triggered via UDP sockets, making it a memory-corruption issue in core networking code.
Impact
An attacker who can trigger the race gains use-after-free conditions in kernel memory, which can lead to privilege escalation or code execution in kernel context. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The CVSS vector is local (AV:L) with low privileges (PR:L) and no user interaction, so it is reached by a local process exercising the affected networking path, not over the network. The description notes UDP sockets are used to make the bug visible.
Exploitation
CVE-2024-36971 is listed in CISA KEV (added 2024-08-07) as an Android kernel remote code execution vulnerability, indicating known exploitation. EPSS 30-day probability is about 2.7 percent (85th percentile), and all references are patches or advisories with no public exploit tag.
What to do
- Apply the upstream Linux kernel patches referenced in the git.kernel.org stable commits and update to a fixed kernel version.
- Apply the vendor (Debian/Android) security updates that backport this fix, and follow CISA KEV required action to mitigate or discontinue use if no fix is available.
- Restrict local access and untrusted code execution on affected systems to reduce the ability to trigger the race.
- Monitor for and prioritize patching of internet-facing or multi-tenant systems where local privilege escalation has the highest impact.
Detection
- Monitor kernel logs for use-after-free, KASAN, or slab corruption reports in networking paths.
- Track patch levels of Linux kernel and Android builds against the fixed stable commits.
- Watch for unexpected privilege escalation or suspicious local processes interacting with UDP socket handling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-36971 to the Known Exploited Vulnerabilities catalog on 7 August 2024 as "Android Kernel Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-36971 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-36971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.