---
cve: "CVE-2024-35897"
severity: "HIGH"
cvss: 7.8
epss: "0.3%"
vendor: "Linux"
kev: false
exploited: false
published: "2024-05-19 09:15:10"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T16:05:46+02:00"
---

# CVE-2024-35897

> 7.8 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: discard table flag update with pending basechain deletion

Hook unregistration is deferred to the commit phase, same occurs with
hook updates triggered by the table dormant flag. When both commands are
combined, this results in deleting a basechain while leaving its hook
still registered in the core.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.4.274
- Kernel ≥ 5.10.215
- Kernel ≥ 5.15.155
- Kernel ≥ 6.1.86
- Kernel ≥ 6.6.26
- Kernel ≥ 6.8.5

## Referenzen

- <https://git.kernel.org/stable/c/e75faf01e22ec7dc671640fa0e0968964fafd2fc>
- <https://git.kernel.org/stable/c/9a3b90904d8a072287480eed4c3ece4b99d64f78>
- <https://git.kernel.org/stable/c/b58d0ac35f6d75ec1db8650a29dfd6f292c11362>
- <https://git.kernel.org/stable/c/6cbbe1ba76ee7e674a86abd43009b083a45838cb>
- <https://git.kernel.org/stable/c/2aeb805a1bcd5f27c8c0d1a9d4d653f16d1506f4>
- <https://git.kernel.org/stable/c/9627fd0c6ea1c446741a33e67bc5709c59923827>
- <https://git.kernel.org/stable/c/7f609f630951b624348373cef99991ce08831927>
- <https://git.kernel.org/stable/c/1bc83a019bbe268be3526406245ec28c2458a518>
- <https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-265688.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-35897) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
