Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not match the flowtable entry because the pppoe header is expected to be at the network header offset. This bug causes a mismatch in the flow table lookup, so pppoe packets enter the classical forwarding path.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.13, < 5.15.157 |
| Fedoraproject | Fedora | 38 |
References
- https://git.kernel.org/stable/c/4ed82dd368ad883dc4284292937b882f044e625dPatch
- https://git.kernel.org/stable/c/6db5dc7b351b9569940cd1cf445e237c42cd6d27Patch
- https://git.kernel.org/stable/c/e3f078103421642fcd5f05c5e70777feb10f000dPatch
- https://git.kernel.org/stable/c/e719b52d0c56989b0f3475a03a6d64f182c85b56Patch
- https://git.kernel.org/stable/c/f1c3c61701a0b12f4906152c1626a5de580ea3d2Patch
- https://git.kernel.org/stable/c/4ed82dd368ad883dc4284292937b882f044e625dPatch
- https://git.kernel.org/stable/c/6db5dc7b351b9569940cd1cf445e237c42cd6d27Patch
- https://git.kernel.org/stable/c/e3f078103421642fcd5f05c5e70777feb10f000dPatch
- https://git.kernel.org/stable/c/e719b52d0c56989b0f3475a03a6d64f182c85b56Patch
- https://git.kernel.org/stable/c/f1c3c61701a0b12f4906152c1626a5de580ea3d2Patch
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
FAQ
What is CVE-2024-27015?
CVE-2024-27015 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not match the flowtable entry because the ppp...
How severe is CVE-2024-27015?
CVE-2024-27015 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-27015?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora.