Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-36937

5.5 · MEDIUM
Published May 30, 2024 linux CWE-476 EPSS 0.22% (13th pctl)

Overview

CVE-2024-36937 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 30, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

xdp: use flags field to disambiguate broadcast redirect

When redirecting a packet using XDP, the bpf_redirect_map() helper will set

up the redirect destination information in struct bpf_redirect_info (using

the __bpf_xdp_redirect_map() helper function), and the xdp_do_redirect()

function will read this information after the XDP program returns and pass

the frame on to the right redirect destination.

When using the BPF_F_BROADCAST flag to do multicast redirect to a whole

map, __bpf_xdp_redirect_map() sets the 'map' pointer in struct

bpf_redirect_info to point to the destination map to be broadcast. And

xdp_do_redirect() reacts to the value of this map pointer to decide whether

it's dealing with a broadcast or a single-value redirect. However, if the

destination map is being destroyed before xdp_do_redirect() is called, the

map pointer will be cleared out (by bpf_clear_redirect_map()) without

waiting for any XDP progr

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.14, < 5.15.159 Affected

Frequently Asked Questions

What is CVE-2024-36937?

CVE-2024-36937 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 30, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2024-36937?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-36937?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-36937?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-36937 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.