CVE-2024-44986

Executive Summary

CVE-2024-44986 exposes a use‑after‑free in the Linux kernel’s IPv6 stack. When skb_expand_head() fails, the skb is freed while its destination (dst) and interface device (idev) may still be referenced, allowing an attacker to exploit dangling pointers. The patch enforces an rcu_read_lock() around the operation to guarantee the dst and idev remain valid, preventing the UAF. No CISA KEV listing yet.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2024-09-04T20:15:07.833 - Last Modified: 2026-09-29T13:17:38.417

Original Description: In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix possible UAF in ip6_finish_output2()

If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed.

We need to hold rcu_read_lock() to make sure the dst and associated idev are alive.

"You, yourself, as much as anybody in the entire universe, deserve your love and affection."

— Buddha
Source: NVD