← Vulnerability feed

Vulnerability record · CVE-2024-36971 · published 10 June 2024

CVE-2024-36971: Linux kernel use-after-free in __dst_negative_advice()

Debian · Debian Linux

The Linux kernel's __dst_negative_advice() clears sk->dst_cache in the wrong order relative to dst_release(), violating RCU rules and allowing a use-after-free. The bug became reachable after a related change and is triggered via UDP sockets, making it a memory-corruption issue in core networking code.

7.8 CVSS 3.1 High CISA KEV since 7 Aug 2024 EPSS 2.7% · top 14.6% CWE-416 · Use after free
7.8CVSS 3.1 base score
2.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order. Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three ->negative_advice() existing methods must perform the sk_dst_reset() themselves. Note the check against NULL dst is centralized in __dst_negative_advice(), there is no need to duplicate it in various callbacks. Many thanks to Clement Lecigne for tracking this issue. This old bug became visible after the blamed commit, using UDP sockets.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is a kernel use-after-free with high CVSS impact and confirmed inclusion in CISA KEV, though exploitation requires local access and the EPSS probability is modest.

What it is

The Linux kernel's __dst_negative_advice() clears sk->dst_cache in the wrong order relative to dst_release(), violating RCU rules and allowing a use-after-free. The bug became reachable after a related change and is triggered via UDP sockets, making it a memory-corruption issue in core networking code.

Impact

An attacker who can trigger the race gains use-after-free conditions in kernel memory, which can lead to privilege escalation or code execution in kernel context. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The CVSS vector is local (AV:L) with low privileges (PR:L) and no user interaction, so it is reached by a local process exercising the affected networking path, not over the network. The description notes UDP sockets are used to make the bug visible.

Exploitation

CVE-2024-36971 is listed in CISA KEV (added 2024-08-07) as an Android kernel remote code execution vulnerability, indicating known exploitation. EPSS 30-day probability is about 2.7 percent (85th percentile), and all references are patches or advisories with no public exploit tag.

What to do

  • Apply the upstream Linux kernel patches referenced in the git.kernel.org stable commits and update to a fixed kernel version.
  • Apply the vendor (Debian/Android) security updates that backport this fix, and follow CISA KEV required action to mitigate or discontinue use if no fix is available.
  • Restrict local access and untrusted code execution on affected systems to reduce the ability to trigger the race.
  • Monitor for and prioritize patching of internet-facing or multi-tenant systems where local privilege escalation has the highest impact.

Detection

  • Monitor kernel logs for use-after-free, KASAN, or slab corruption reports in networking paths.
  • Track patch levels of Linux kernel and Android builds against the fixed stable commits.
  • Watch for unexpected privilege escalation or suspicious local processes interacting with UDP socket handling.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-36971 to the Known Exploited Vulnerabilities catalog on 7 August 2024 as "Android Kernel Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-36971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-36971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.