{"id":"DEBIAN-CVE-2024-42272","details":"In the Linux kernel, the following vulnerability has been resolved:  sched: act_ct: take care of padding in struct zones_ht_key  Blamed commit increased lookup key size from 2 bytes to 16 bytes, because zones_ht_key got a struct net pointer.  Make sure rhashtable_lookup() is not using the padding bytes which are not initialized.   BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline]  BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline]  BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline]  BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]  BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329   rht_ptr_rcu include/linux/rhashtable.h:376 [inline]   __rhashtable_lookup include/linux/rhashtable.h:607 [inline]   rhashtable_lookup include/linux/rhashtable.h:646 [inline]   rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]   tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329   tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408   tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425   tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488   tcf_action_add net/sched/act_api.c:2061 [inline]   tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118   rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647   netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550   rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665   netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]   netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357   netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901   sock_sendmsg_nosec net/socket.c:730 [inline]   __sock_sendmsg+0x30f/0x380 net/socket.c:745   ____sys_sendmsg+0x877/0xb60 net/socket.c:2597   ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651   __sys_sendmsg net/socket.c:2680 [inline]   __do_sys_sendmsg net/socket.c:2689 [inline]   __se_sys_sendmsg net/socket.c:2687 [inline]   __x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2687   x64_sys_call+0x2dd6/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:47   do_syscall_x64 arch/x86/entry/common.c:52 [inline]   do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Local variable key created at:   tcf_ct_flow_table_get+0x4a/0x2260 net/sched/act_ct.c:324   tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408","modified":"2026-09-15T09:03:10.467485049Z","published":"2024-08-17T09:15:08.370Z","upstream":["CVE-2024-42272"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-42272"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.106-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42272.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42272.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42272.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}