CVE-2024-41040
A use‑after‑free bug in the Linux kernel’s traffic‑control subsystem could let an attacker crash the system or potentially execute code. The flaw occurs when a connection‑track entry is freed but still referenced during packet classification.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux kernel users, especially those running older kernel versions that have not applied the patch for the net/sched use‑after‑free bug.
Real-world impact
An attacker could cause a denial of service by sending crafted network packets that trigger the use‑after‑free, potentially leading to a kernel crash or arbitrary code execution.
Why this severity
The CVSS score of 9.8 reflects the high impact (confidentiality, integrity, availability) and the fact that the vulnerability is exploitable remotely with no authentication or user interaction.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the net/sched use‑after‑free fix.
NVD-referenced vendor advisory
Timeline
- Jul 29, 2024 · Jul 29, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/26488172b0292bed83…patch
- git.kernel.org/stable/c/2b4d68df3f57ea746c…patch
- git.kernel.org/stable/c/4e71b10a100861fb27…patch
- git.kernel.org/stable/c/799a34901b634008db…patch
- git.kernel.org/stable/c/b81a523d54ea689414…patch
- git.kernel.org/stable/c/ef472cc6693b16b202…patch
- lists.debian.org/debian-lts-announce/2025/01…