netfilter: ipset: add missing range check in bitmap_ip_uadt
When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists,
the values of ip and ip_to are slightly swapped. Therefore, the range check
for ip should be done later, but this part is missing and it seems that the
vulnerability occurs.
So we should add missing range checks and remove unnecessary range checks.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4075-1 | linux security update |
Debian DLA |
DLA-4076-1 | linux-6.1 security update |
EUVD |
EUVD-2024-51813 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefore, the range check for ip should be done later, but this part is missing and it seems that the vulnerability occurs. So we should add missing range checks and remove unnecessary range checks. |
Ubuntu USN |
USN-7232-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-7233-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7233-2 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-7233-3 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-7234-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7234-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-7234-3 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-7234-4 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-7234-5 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7235-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7235-2 | Linux kernel (Azure) Unknown kernel vulnerabilities |
Ubuntu USN |
USN-7235-3 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-7236-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7236-2 | Linux kernel (Low Latency) vulnerabilities |
Ubuntu USN |
USN-7236-3 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-7237-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-7262-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7262-2 | Linux kernel (KVM) vulnerabilities |
Ubuntu USN |
USN-7276-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7277-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7295-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7308-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7310-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7311-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-7389-1 | Linux kernel (NVIDIA Tegra) vulnerabilities |
Ubuntu USN |
USN-7390-1 | Linux kernel (Xilinx ZynqMP) vulnerabilities |
Ubuntu USN |
USN-7413-1 | Linux kernel (IoT) vulnerabilities |
Ubuntu USN |
USN-7468-1 | Linux kernel (Azure, N-Series) vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 26 Jun 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/o:redhat:enterprise_linux:9 |
Tue, 03 Jun 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:rhel_e4s:9.0 cpe:/o:redhat:rhel_eus:9.2 cpe:/o:redhat:rhel_eus:9.4 |
Tue, 20 May 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Els
|
|
| CPEs | cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_e4s:9.0::nfv cpe:/a:redhat:rhel_tus:8.4::nfv cpe:/o:redhat:rhel_aus:7.7 cpe:/o:redhat:rhel_aus:8.4 cpe:/o:redhat:rhel_e4s:8.4 cpe:/o:redhat:rhel_els:7 cpe:/o:redhat:rhel_tus:8.4 |
|
| Vendors & Products |
Redhat rhel Els
|
Fri, 16 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Extras Rt Els Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:rhel_extras_rt_els:7 cpe:/o:redhat:rhel_aus:8.2 cpe:/o:redhat:rhel_aus:8.6 cpe:/o:redhat:rhel_e4s:8.6 cpe:/o:redhat:rhel_eus:8.8 cpe:/o:redhat:rhel_tus:8.6 |
|
| Vendors & Products |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Extras Rt Els Redhat rhel Tus |
Wed, 14 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat rhel Eus |
|
| CPEs | cpe:/a:redhat:enterprise_linux:8::nfv cpe:/a:redhat:rhel_eus:9.2 cpe:/a:redhat:rhel_eus:9.2::nfv cpe:/a:redhat:rhel_eus:9.4 cpe:/o:redhat:enterprise_linux:8 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat rhel Eus |
Sat, 26 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
threat_severity
|
threat_severity
|
Fri, 20 Dec 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Thu, 19 Dec 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 14 Dec 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 10 Dec 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linux
Linux linux Kernel |
|
| Metrics |
cvssV3_1
|
Mon, 09 Dec 2024 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 06 Dec 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefore, the range check for ip should be done later, but this part is missing and it seems that the vulnerability occurs. So we should add missing range checks and remove unnecessary range checks. | |
| Title | netfilter: ipset: add missing range check in bitmap_ip_uadt | |
| References |
|
Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2025-11-03T20:46:21.162Z
Reserved: 2024-11-19T17:17:24.997Z
Link: CVE-2024-53141
No data.
Status : Modified
Published: 2024-12-06T10:15:06.050
Modified: 2025-11-03T21:17:30.337
Link: CVE-2024-53141
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN