CVE-2024-35890 (GCVE-0-2024-35890)
Vulnerability from cvelistv5
Published
2024-05-19 08:34
Modified
2026-08-05 11:30
Summary
In the Linux kernel, the following vulnerability has been resolved: gro: fix ownership transfer If packets are GROed with fraglist they might be segmented later on and continue their journey in the stack. In skb_segment_list those skbs can be reused as-is. This is an issue as their destructor was removed in skb_gro_receive_list but not the reference to their socket, and then they can't be orphaned. Fix this by also removing the reference to the socket. For example this could be observed, kernel BUG at include/linux/skbuff.h:3131! (skb_orphan) RIP: 0010:ip6_rcv_core+0x11bc/0x19a0 Call Trace: ipv6_list_rcv+0x250/0x3f0 __netif_receive_skb_list_core+0x49d/0x8f0 netif_receive_skb_list_internal+0x634/0xd40 napi_complete_done+0x1d2/0x7d0 gro_cell_poll+0x118/0x1f0 A similar construction is found in skb_gro_receive, apply the same change there.
Impacted products
Vendor Product Version
Linux Linux Version: 5e10da5385d20c4bae587bc2921e5fdd9655d5fc
Version: 5e10da5385d20c4bae587bc2921e5fdd9655d5fc
Version: 5e10da5385d20c4bae587bc2921e5fdd9655d5fc
Version: 5e10da5385d20c4bae587bc2921e5fdd9655d5fc
Version: 5e10da5385d20c4bae587bc2921e5fdd9655d5fc
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-35890",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-23T17:20:18.616682Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:33:50.532Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-05-09T20:03:34.797Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/d225b0ac96dc40d7e8ae2bc227eb2c56e130975f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2eeab8c47c3c0276e0746bc382f405c9a236a5ad"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/5b3b67f731296027cceb3efad881ae281213f86f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ed4cccef64c1d0d5b91e69f7a8a6697c3a865486"
          },
          {
            "url": "https://security.netapp.com/advisory/ntap-20250509-0008/"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/core/gro.c",
            "net/ipv4/udp_offload.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d225b0ac96dc40d7e8ae2bc227eb2c56e130975f",
              "status": "affected",
              "version": "5e10da5385d20c4bae587bc2921e5fdd9655d5fc",
              "versionType": "git"
            },
            {
              "lessThan": "2eeab8c47c3c0276e0746bc382f405c9a236a5ad",
              "status": "affected",
              "version": "5e10da5385d20c4bae587bc2921e5fdd9655d5fc",
              "versionType": "git"
            },
            {
              "lessThan": "fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6",
              "status": "affected",
              "version": "5e10da5385d20c4bae587bc2921e5fdd9655d5fc",
              "versionType": "git"
            },
            {
              "lessThan": "5b3b67f731296027cceb3efad881ae281213f86f",
              "status": "affected",
              "version": "5e10da5385d20c4bae587bc2921e5fdd9655d5fc",
              "versionType": "git"
            },
            {
              "lessThan": "ed4cccef64c1d0d5b91e69f7a8a6697c3a865486",
              "status": "affected",
              "version": "5e10da5385d20c4bae587bc2921e5fdd9655d5fc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/core/gro.c",
            "net/ipv4/udp_offload.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "lessThan": "5.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.154",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.85",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.26",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.154",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.85",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.26",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.5",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngro: fix ownership transfer\n\nIf packets are GROed with fraglist they might be segmented later on and\ncontinue their journey in the stack. In skb_segment_list those skbs can\nbe reused as-is. This is an issue as their destructor was removed in\nskb_gro_receive_list but not the reference to their socket, and then\nthey can\u0027t be orphaned. Fix this by also removing the reference to the\nsocket.\n\nFor example this could be observed,\n\n  kernel BUG at include/linux/skbuff.h:3131!  (skb_orphan)\n  RIP: 0010:ip6_rcv_core+0x11bc/0x19a0\n  Call Trace:\n   ipv6_list_rcv+0x250/0x3f0\n   __netif_receive_skb_list_core+0x49d/0x8f0\n   netif_receive_skb_list_internal+0x634/0xd40\n   napi_complete_done+0x1d2/0x7d0\n   gro_cell_poll+0x118/0x1f0\n\nA similar construction is found in skb_gro_receive, apply the same\nchange there."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The skbs that carry a socket reference into GRO are locally generated (`destructor == sock_wfree`), since remotely received packets are already orphaned in `ip_rcv_core()`/`ip6_rcv_core()`; the attacker must therefore send UDP traffic from a local socket over a veth pair. No remote peer can supply the sk-owning skbs directly.\nAC:L - The attacker controls every precondition \u2014 creating the veth pair, enabling GRO/rx-gro-list in their own netns, and sending a UDP burst that GRO deterministically aggregates and the stack then re-segments. No race or unknowable memory state is required for the crash, and the socket free timing for the UAF is also attacker-controlled (send, then close).\nPR:L - An unprivileged user can obtain CAP_NET_ADMIN in a private netns via `unshare -Urn`, which is sufficient to create the veth pair and to run `ethtool -K` (gated only by `ns_capable(net-\u003euser_ns, CAP_NET_ADMIN)`); the triggering traffic is then an ordinary UDP send. The resulting panic/UAF affects the whole host, not just the namespace.\nUI:N - The entire sequence is driven by the attacker\u0027s own process \u2014 interface configuration and packet transmission \u2014 with no action from any other user or administrator.\nS:U - The corruption and the crash occur within the kernel\u0027s own security authority; no hypervisor, IOMMU, or other authority boundary is crossed even though the trigger originates inside a container/netns.\nC:H - The detached segments retain an unreferenced `struct sock *`, so after `sock_wfree()` releases the last `sk_wmem_alloc` charge the pointer dangles; subsequent reads of `skb-\u003esk` (e.g. `sk_fullsock()`, `sk_validate_xmit_skb()`) read freed, sprayable slab memory, giving a use-after-free disclosure primitive.\nI:H - The same dangling `sk` is used for an indirect call (`sk-\u003esk_validate_xmit_skb(sk, dev, skb)`) and for accounting updates on a reallocated object, so a heap-sprayed sock allocation yields control-flow hijack / write-into-freed-object primitives typical of a use-after-free.\nA:H - The documented and easily reproduced result is `BUG_ON(skb-\u003esk)` in `skb_orphan()` reached from `ip6_rcv_core()` under NAPI/softirq context, which oopses in interrupt context and panics the machine; it can be re-triggered at will."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:30:44.493Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d225b0ac96dc40d7e8ae2bc227eb2c56e130975f"
        },
        {
          "url": "https://git.kernel.org/stable/c/2eeab8c47c3c0276e0746bc382f405c9a236a5ad"
        },
        {
          "url": "https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6"
        },
        {
          "url": "https://git.kernel.org/stable/c/5b3b67f731296027cceb3efad881ae281213f86f"
        },
        {
          "url": "https://git.kernel.org/stable/c/ed4cccef64c1d0d5b91e69f7a8a6697c3a865486"
        }
      ],
      "title": "gro: fix ownership transfer",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-35890",
    "datePublished": "2024-05-19T08:34:46.085Z",
    "dateReserved": "2024-05-17T13:50:33.113Z",
    "dateUpdated": "2026-08-05T11:30:44.493Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d225b0ac96dc40d7e8ae2bc227eb2c56e130975f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2eeab8c47c3c0276e0746bc382f405c9a236a5ad\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/5b3b67f731296027cceb3efad881ae281213f86f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/ed4cccef64c1d0d5b91e69f7a8a6697c3a865486\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://security.netapp.com/advisory/ntap-20250509-0008/\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-05-09T20:03:34.797Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-35890\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-23T17:20:18.616682Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-23T19:01:25.743Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"gro: fix ownership transfer\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The skbs that carry a socket reference into GRO are locally generated (`destructor == sock_wfree`), since remotely received packets are already orphaned in `ip_rcv_core()`/`ip6_rcv_core()`; the attacker must therefore send UDP traffic from a local socket over a veth pair. No remote peer can supply the sk-owning skbs directly.\\nAC:L - The attacker controls every precondition \\u2014 creating the veth pair, enabling GRO/rx-gro-list in their own netns, and sending a UDP burst that GRO deterministically aggregates and the stack then re-segments. No race or unknowable memory state is required for the crash, and the socket free timing for the UAF is also attacker-controlled (send, then close).\\nPR:L - An unprivileged user can obtain CAP_NET_ADMIN in a private netns via `unshare -Urn`, which is sufficient to create the veth pair and to run `ethtool -K` (gated only by `ns_capable(net-\u003euser_ns, CAP_NET_ADMIN)`); the triggering traffic is then an ordinary UDP send. The resulting panic/UAF affects the whole host, not just the namespace.\\nUI:N - The entire sequence is driven by the attacker\u0027s own process \\u2014 interface configuration and packet transmission \\u2014 with no action from any other user or administrator.\\nS:U - The corruption and the crash occur within the kernel\u0027s own security authority; no hypervisor, IOMMU, or other authority boundary is crossed even though the trigger originates inside a container/netns.\\nC:H - The detached segments retain an unreferenced `struct sock *`, so after `sock_wfree()` releases the last `sk_wmem_alloc` charge the pointer dangles; subsequent reads of `skb-\u003esk` (e.g. `sk_fullsock()`, `sk_validate_xmit_skb()`) read freed, sprayable slab memory, giving a use-after-free disclosure primitive.\\nI:H - The same dangling `sk` is used for an indirect call (`sk-\u003esk_validate_xmit_skb(sk, dev, skb)`) and for accounting updates on a reallocated object, so a heap-sprayed sock allocation yields control-flow hijack / write-into-freed-object primitives typical of a use-after-free.\\nA:H - The documented and easily reproduced result is `BUG_ON(skb-\u003esk)` in `skb_orphan()` reached from `ip6_rcv_core()` under NAPI/softirq context, which oopses in interrupt context and panics the machine; it can be re-triggered at will.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5e10da5385d20c4bae587bc2921e5fdd9655d5fc\", \"lessThan\": \"d225b0ac96dc40d7e8ae2bc227eb2c56e130975f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5e10da5385d20c4bae587bc2921e5fdd9655d5fc\", \"lessThan\": \"2eeab8c47c3c0276e0746bc382f405c9a236a5ad\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5e10da5385d20c4bae587bc2921e5fdd9655d5fc\", \"lessThan\": \"fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5e10da5385d20c4bae587bc2921e5fdd9655d5fc\", \"lessThan\": \"5b3b67f731296027cceb3efad881ae281213f86f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5e10da5385d20c4bae587bc2921e5fdd9655d5fc\", \"lessThan\": \"ed4cccef64c1d0d5b91e69f7a8a6697c3a865486\", \"versionType\": \"git\"}], \"programFiles\": [\"net/core/gro.c\", \"net/ipv4/udp_offload.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.15\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.15\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.154\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.85\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.26\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/core/gro.c\", \"net/ipv4/udp_offload.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d225b0ac96dc40d7e8ae2bc227eb2c56e130975f\"}, {\"url\": \"https://git.kernel.org/stable/c/2eeab8c47c3c0276e0746bc382f405c9a236a5ad\"}, {\"url\": \"https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6\"}, {\"url\": \"https://git.kernel.org/stable/c/5b3b67f731296027cceb3efad881ae281213f86f\"}, {\"url\": \"https://git.kernel.org/stable/c/ed4cccef64c1d0d5b91e69f7a8a6697c3a865486\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ngro: fix ownership transfer\\n\\nIf packets are GROed with fraglist they might be segmented later on and\\ncontinue their journey in the stack. In skb_segment_list those skbs can\\nbe reused as-is. This is an issue as their destructor was removed in\\nskb_gro_receive_list but not the reference to their socket, and then\\nthey can\u0027t be orphaned. Fix this by also removing the reference to the\\nsocket.\\n\\nFor example this could be observed,\\n\\n  kernel BUG at include/linux/skbuff.h:3131!  (skb_orphan)\\n  RIP: 0010:ip6_rcv_core+0x11bc/0x19a0\\n  Call Trace:\\n   ipv6_list_rcv+0x250/0x3f0\\n   __netif_receive_skb_list_core+0x49d/0x8f0\\n   netif_receive_skb_list_internal+0x634/0xd40\\n   napi_complete_done+0x1d2/0x7d0\\n   gro_cell_poll+0x118/0x1f0\\n\\nA similar construction is found in skb_gro_receive, apply the same\\nchange there.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.154\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.85\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.26\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.5\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"5.15\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:30:44.493Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-35890\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:30:44.493Z\", \"dateReserved\": \"2024-05-17T13:50:33.113Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-19T08:34:46.085Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…