CVE-2024-36031

CRITICAL EPSS 50.2%
Published May 30, 20242y ago · Modified Jun 17, 20262w ago
9.8 CVSS 3.1
Critical
Find Similar
Published May 30, 2024 2y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem for DNS resolution as the expiration set by user-space is overwritten to TIME64_MAX, disabling further DNS updates. Fix this by restoring the condition that key_set_expiry is only called when the pre-parser sets a specific expiry.

CVSS Details

Base Score
9.8
Exploitability
3.9
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
50.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-324

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥5.10.206  –  <5.10.217
linuxlinux_kernel*≥5.15.146  –  <5.15.159
linuxlinux_kernel*≥6.1.70  –  <6.1.91
linuxlinux_kernel*≥6.6.9  –  <6.6.31
linuxlinux_kernel*≥6.7  –  <6.8.10
linuxlinux_kernel*≥6.9  –  <6.9.1

References 8

  • git.kernel.org https://git.kernel.org/stable/c/25777f3f4e1f371d16a594925f31e37ce07b6ec7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/939a08bcd4334bad4b201e60bd0ae1f278d71d41
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9da27fb65a14c18efd4473e2e82b76b53ba60252
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ad2011ea787928b2accb5134f1e423b11fe80a8a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cc219cb8afbc40ec100c0de941047bb29373126a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e4519a016650e952ad9eb27937f8c447d5a4e06d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ed79b93f725cd0da39a265dc23d77add1527b9be
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/25777f3f4e1f371d16a594925f31e37ce07b6ec7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/939a08bcd4334bad4b201e60bd0ae1f278d71d41
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9da27fb65a14c18efd4473e2e82b76b53ba60252
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ad2011ea787928b2accb5134f1e423b11fe80a8a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cc219cb8afbc40ec100c0de941047bb29373126a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e4519a016650e952ad9eb27937f8c447d5a4e06d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ed79b93f725cd0da39a265dc23d77add1527b9be
    Patch