Description Preview
In the Linux kernel, the vulnerability identified as CVE-2024-46711 has been resolved in the mptcp: pm module. The issue pertains to the handling of ID 0 endp usage after multiple re-creations. Specifically, the decrementing of 'local_addr_used' and 'add_addr_accepted' for addresses not associated with the initial subflow (ID0) is necessary, as the source and destination addresses of the initial subflows are known from the start and should not be counted as additional local addresses being used or ADD_ADDR being accepted. The modification ensures that these counters are not incremented when the entrypoint used by the initial subflow is removed and re-added during a connection, allowing for the removal and re-addition of the entrypoint more than once.
Overview
The vulnerability in the Linux kernel's mptcp: pm module addresses the incorrect handling of ID 0 endp usage after multiple re-creations, impacting certain versions of the kernel.
Remediation
To remediate this vulnerability, affected users are advised to update their Linux kernel to versions that include the fix for the mptcp: pm module. Specifically, users should ensure that their kernel versions are equal to or greater than the fixed versions specified in the CVE details.
References
- Advisory Details: https://git.kernel.org/stable/c/c9c744666f7308a4daba520191e29d395260bcfe
- Advisory Details: https://git.kernel.org/stable/c/53e2173172d26c0617b29dd83618b71664bed1fb
- Advisory Details: https://git.kernel.org/stable/c/119806ae4e46cf239db8e6ad92bc2fd3daae86dc
- Advisory Details: https://git.kernel.org/stable/c/9366922adc6a71378ca01f898c41be295309f044
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Public AdministrationPublic Administration
- Health Care & Social AssistanceHealth Care & Social Assistance
- Finance and InsuranceFinance and Insurance
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Retail TradeRetail Trade
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Transportation & WarehousingTransportation & Warehousing
- Educational ServicesEducational Services
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Other Services (except Public Administration)Other Services (except Public Administration)
- InformationInformation
- UtilitiesUtilities
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Wholesale TradeWholesale Trade