ID

VAR-202405-2071


CVE

CVE-2024-36929


TITLE

Debian In products from multiple vendors such as NULL  Pointer dereference vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2024-030005

DESCRIPTION

In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb_copy_expand, in order to prevent a crash on a potential later call to skb_gso_segment. Information handled by the software will not be rewritten. In addition, the software may stop functioning completely. Furthermore, attacks that exploit this vulnerability will not affect other software. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs). Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server. ========================================================================== Ubuntu Security Notice USN-6950-1 August 08, 2024 linux, linux-aws, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-intel-iotg: Linux kernel for Intel IoT platforms - linux-kvm: Linux kernel for cloud environments - linux-lowlatency: Linux low latency kernel - linux-nvidia: Linux kernel for NVIDIA systems - linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms - linux-lowlatency-hwe-5.15: Linux low latency kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - Block layer subsystem; - Bluetooth drivers; - Clock framework and drivers; - FireWire subsystem; - GPU drivers; - InfiniBand drivers; - Multiple devices driver; - EEPROM drivers; - Network drivers; - Pin controllers subsystem; - Remote Processor subsystem; - S/390 drivers; - SCSI drivers; - 9P distributed file system; - Network file system client; - SMB network file system; - Socket messages infrastructure; - Dynamic debug library; - Bluetooth subsystem; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - NSH protocol; - Phonet protocol; - TIPC protocol; - Wireless networking; - Key management; - ALSA framework; - HD-audio driver; (CVE-2024-36883, CVE-2024-36940, CVE-2024-36902, CVE-2024-36975, CVE-2024-36964, CVE-2024-36938, CVE-2024-36931, CVE-2024-35848, CVE-2024-26900, CVE-2024-36967, CVE-2024-36904, CVE-2024-27398, CVE-2024-36031, CVE-2023-52585, CVE-2024-36886, CVE-2024-36937, CVE-2024-36954, CVE-2024-36916, CVE-2024-36905, CVE-2024-36959, CVE-2024-26980, CVE-2024-26936, CVE-2024-36928, CVE-2024-36889, CVE-2024-36929, CVE-2024-36933, CVE-2024-27399, CVE-2024-36946, CVE-2024-36906, CVE-2024-36965, CVE-2024-36957, CVE-2024-36941, CVE-2024-36897, CVE-2024-36952, CVE-2024-36947, CVE-2024-36950, CVE-2024-36880, CVE-2024-36017, CVE-2023-52882, CVE-2024-36969, CVE-2024-38600, CVE-2024-36955, CVE-2024-36960, CVE-2024-27401, CVE-2024-36919, CVE-2024-36934, CVE-2024-35947, CVE-2024-36953, CVE-2024-36944, CVE-2024-36939) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1050-gkeop 5.15.0-1050.57 linux-image-5.15.0-1062-intel-iotg 5.15.0-1062.68 linux-image-5.15.0-1062-nvidia 5.15.0-1062.63 linux-image-5.15.0-1062-nvidia-lowlatency 5.15.0-1062.63 linux-image-5.15.0-1064-gke 5.15.0-1064.70 linux-image-5.15.0-1064-kvm 5.15.0-1064.69 linux-image-5.15.0-1066-gcp 5.15.0-1066.74 linux-image-5.15.0-1067-aws 5.15.0-1067.73 linux-image-5.15.0-118-generic 5.15.0-118.128 linux-image-5.15.0-118-generic-64k 5.15.0-118.128 linux-image-5.15.0-118-generic-lpae 5.15.0-118.128 linux-image-5.15.0-118-lowlatency 5.15.0-118.128 linux-image-5.15.0-118-lowlatency-64k 5.15.0-118.128 linux-image-aws-lts-22.04 5.15.0.1067.67 linux-image-gcp-lts-22.04 5.15.0.1066.62 linux-image-generic 5.15.0.118.118 linux-image-generic-64k 5.15.0.118.118 linux-image-generic-lpae 5.15.0.118.118 linux-image-gke 5.15.0.1064.63 linux-image-gke-5.15 5.15.0.1064.63 linux-image-gkeop 5.15.0.1050.49 linux-image-gkeop-5.15 5.15.0.1050.49 linux-image-intel-iotg 5.15.0.1062.62 linux-image-kvm 5.15.0.1064.60 linux-image-lowlatency 5.15.0.118.108 linux-image-lowlatency-64k 5.15.0.118.108 linux-image-nvidia 5.15.0.1062.62 linux-image-nvidia-lowlatency 5.15.0.1062.62 linux-image-virtual 5.15.0.118.118 Ubuntu 20.04 LTS linux-image-5.15.0-1062-intel-iotg 5.15.0-1062.68~20.04.1 linux-image-5.15.0-1066-gcp 5.15.0-1066.74~20.04.1 linux-image-5.15.0-118-lowlatency 5.15.0-118.128~20.04.1 linux-image-5.15.0-118-lowlatency-64k 5.15.0-118.128~20.04.1 linux-image-gcp 5.15.0.1066.74~20.04.1 linux-image-intel 5.15.0.1062.68~20.04.1 linux-image-intel-iotg 5.15.0.1062.68~20.04.1 linux-image-lowlatency-64k-hwe-20.04 5.15.0.118.128~20.04.1 linux-image-lowlatency-hwe-20.04 5.15.0.118.128~20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6950-1 CVE-2023-52585, CVE-2023-52882, CVE-2024-26900, CVE-2024-26936, CVE-2024-26980, CVE-2024-27398, CVE-2024-27399, CVE-2024-27401, CVE-2024-35848, CVE-2024-35947, CVE-2024-36017, CVE-2024-36031, CVE-2024-36880, CVE-2024-36883, CVE-2024-36886, CVE-2024-36889, CVE-2024-36897, CVE-2024-36902, CVE-2024-36904, CVE-2024-36905, CVE-2024-36906, CVE-2024-36916, CVE-2024-36919, CVE-2024-36928, CVE-2024-36929, CVE-2024-36931, CVE-2024-36933, CVE-2024-36934, CVE-2024-36937, CVE-2024-36938, CVE-2024-36939, CVE-2024-36940, CVE-2024-36941, CVE-2024-36944, CVE-2024-36946, CVE-2024-36947, CVE-2024-36950, CVE-2024-36952, CVE-2024-36953, CVE-2024-36954, CVE-2024-36955, CVE-2024-36957, CVE-2024-36959, CVE-2024-36960, CVE-2024-36964, CVE-2024-36965, CVE-2024-36967, CVE-2024-36969, CVE-2024-36975, CVE-2024-38600 Package Information: https://launchpad.net/ubuntu/+source/linux/5.15.0-118.128 https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1067.73 https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1066.74 https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1064.70 https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1050.57 https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1062.68 https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1064.69 https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-118.128 https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1062.63 https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1066.74~20.04.1 https://launchpad.net/ubuntu/+source/linux-intel-iotg-5.15/5.15.0-1062.68~20.04.1 https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-118.128~20.04.1

Trust: 2.52

sources: NVD: CVE-2024-36929 // JVNDB: JVNDB-2024-030005 // CNVD: CNVD-2025-19346 // PACKETSTORM: 180029 // PACKETSTORM: 180319 // PACKETSTORM: 180092 // PACKETSTORM: 180084

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-19346

AFFECTED PRODUCTS

vendor:linuxmodel:kernelscope:ltversion:5.15.159

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.11

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.1.91

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.10.217

Trust: 1.0

vendor:linuxmodel:kernelscope:eqversion:6.9

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.6

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.2

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:10.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.16

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.7

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.8.10

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.6.31

Trust: 1.0

vendor:linuxmodel:kernelscope: - version: -

Trust: 0.8

vendor:debianmodel:gnu/linuxscope: - version: -

Trust: 0.8

vendor:siemensmodel:ruggedcom rst2428pscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xc-300/xr-300/xc-400/xr-500wg/xr-500 familyscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xcm-/xrm-/xch-/xrh-300 familyscope:ltversion:v3.1

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-030005 // NVD: CVE-2024-36929

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-36929
value: MEDIUM

Trust: 1.0

NVD: CVE-2024-36929
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2025-19346
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-19346
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-36929
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2024-36929
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-030005 // NVD: CVE-2024-36929

PROBLEMTYPE DATA

problemtype:CWE-476

Trust: 1.0

problemtype:NULL Pointer dereference (CWE-476) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-030005 // NVD: CVE-2024-36929

PATCH

title:[SECURITY] [DLA 3843-1] linux-5.10 security update NetAppNetApp Advisoryurl:https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html

Trust: 0.8

title:Patch for Multiple vulnerabilities in Siemens SINEC OS third-party componentsurl:https://www.cnvd.org.cn/patchInfo/show/723071

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-030005

EXTERNAL IDS

db:NVDid:CVE-2024-36929

Trust: 3.0

db:SIEMENSid:SSA-613116

Trust: 1.6

db:SIEMENSid:SSA-265688

Trust: 1.0

db:JVNDBid:JVNDB-2024-030005

Trust: 0.8

db:CNVDid:CNVD-2025-19346

Trust: 0.6

db:PACKETSTORMid:180029

Trust: 0.1

db:PACKETSTORMid:180319

Trust: 0.1

db:PACKETSTORMid:180092

Trust: 0.1

db:PACKETSTORMid:180084

Trust: 0.1

sources: CNVD: CNVD-2025-19346 // PACKETSTORM: 180029 // PACKETSTORM: 180319 // PACKETSTORM: 180092 // PACKETSTORM: 180084 // JVNDB: JVNDB-2024-030005 // NVD: CVE-2024-36929

REFERENCES

url:https://git.kernel.org/stable/c/aea5e2669c2863fdd8679c40ee310b3bcaa85aec

Trust: 1.8

url:https://git.kernel.org/stable/c/d091e579b864fa790dd6a0cd537a22c383126681

Trust: 1.8

url:https://git.kernel.org/stable/c/c7af99cc21923a9650533c9d77265c8dd683a533

Trust: 1.8

url:https://git.kernel.org/stable/c/cfe34d86ef9765c388f145039006bb79b6c81ac6

Trust: 1.8

url:https://git.kernel.org/stable/c/989bf6fd1e1d058e73a364dce1a0c53d33373f62

Trust: 1.8

url:https://git.kernel.org/stable/c/faa83a7797f06cefed86731ba4baa3b4dfdc06c1

Trust: 1.8

url:https://cert-portal.siemens.com/productcert/html/ssa-613116.html

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2024-36929

Trust: 1.2

url:https://security.netapp.com/advisory/ntap-20240905-0010/

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-265688.html

Trust: 1.0

url:https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-36017

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36880

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-26980

Trust: 0.4

url:https://ubuntu.com/security/notices/usn-6950-1

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36916

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36897

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-26936

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2023-52585

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36031

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36919

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36906

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-26900

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-35848

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-36933

Trust: 0.3

url:https://ubuntu.com/security/notices/usn-6950-2

Trust: 0.3

url:https://ubuntu.com/security/notices/usn-6950-3

Trust: 0.2

url:https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1050.57

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-intel-iotg-5.15/5.15.0-1062.68~20.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1066.74~20.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-118.128

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1066.74

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1064.69

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux/5.15.0-118.128

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-118.128~20.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1064.70

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1067.73

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1062.68

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1062.63

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2024-36902

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-6950-4

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-hwe-5.15/5.15.0-118.128~20.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1065.71

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-ibm-5.15/5.15.0-1060.63~20.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1060.63

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-raspi/5.15.0-1060.63

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-aws-5.15/5.15.0-1067.73~20.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-gkeop-5.15/5.15.0-1050.57~20.04.1

Trust: 0.1

sources: CNVD: CNVD-2025-19346 // PACKETSTORM: 180029 // PACKETSTORM: 180319 // PACKETSTORM: 180092 // PACKETSTORM: 180084 // JVNDB: JVNDB-2024-030005 // NVD: CVE-2024-36929

CREDITS

Ubuntu

Trust: 0.4

sources: PACKETSTORM: 180029 // PACKETSTORM: 180319 // PACKETSTORM: 180092 // PACKETSTORM: 180084

SOURCES

db:CNVDid:CNVD-2025-19346
db:PACKETSTORMid:180029
db:PACKETSTORMid:180319
db:PACKETSTORMid:180092
db:PACKETSTORMid:180084
db:JVNDBid:JVNDB-2024-030005
db:NVDid:CVE-2024-36929

LAST UPDATE DATE

2026-06-19T19:56:16.088000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-22T00:00:00
db:JVNDBid:JVNDB-2024-030005date:2026-01-27T08:37:00
db:NVDid:CVE-2024-36929date:2026-05-12T12:16:50.373

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-12T00:00:00
db:PACKETSTORMid:180029date:2024-08-09T14:49:01
db:PACKETSTORMid:180319date:2024-08-22T14:40:42
db:PACKETSTORMid:180092date:2024-08-14T14:34:19
db:PACKETSTORMid:180084date:2024-08-13T15:15:45
db:JVNDBid:JVNDB-2024-030005date:2026-01-27T00:00:00
db:NVDid:CVE-2024-36929date:2024-05-30T16:15:16.133