---
id: CVE-2024-36903
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: Fix potential uninit-value access in __ip6_make_skb()

  As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in
  __ip_make_skb()") for IPv4, check …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: Fix potential uninit-value access in __ip6_make_skb()

  As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in
  __ip_make_skb()") for IPv4, check …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-908
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.14.313, < 4.15'
  - 'linux_kernel >= 4.19.281, < 4.20'
  - 'linux_kernel >= 5.4.241, < 5.5'
  - 'linux_kernel >= 5.10.178, < 5.11'
  - 'linux_kernel >= 5.15.107, < 5.16'
  - 'linux_kernel >= 6.1.24, < 6.2'
  - 'linux_kernel >= 6.2.11, < 6.6.31'
  - 'linux_kernel >= 6.7, < 6.8.10'
  - linux_kernel = 6.9
patched:
  - linux_kernel 6.8.10
published: '2024-05-30'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-36903'
references:
  - url: 'https://git.kernel.org/stable/c/2367bf254f3a27ecc6e229afd7a8b0a1395f7be3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/40e5444a3ac315b60e94d82226b73cd82145d09e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e13d3a9c25b7080f8a619f961e943fe08c2672c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/59d74c843ebf46264c7903726cf6f2673a93b07a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/68c8ba16ab712eb709c6bab80ff151079d11d97a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a05c1ede50e9656f0752e523c7b54f3a3489e9a8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2367bf254f3a27ecc6e229afd7a8b0a1395f7be3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/4e13d3a9c25b7080f8a619f961e943fe08c2672c'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/68c8ba16ab712eb709c6bab80ff151079d11d97a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
epss: 0.0023
epssPercentile: 0.1226
ingestedAt: '2026-07-14T13:36:54.444Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-05-30T18:50:05.807509Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ipv6: Fix potential uninit-value access in __ip6_make_skb()

As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in
__ip_make_skb()") for IPv4, check FLOWI_FLAG_KNOWN_NH on fl6->flowi6_flags
instead of testing HDRINCL on the socket to avoid a race condition which
causes uninit-value access.

## Affected

- `linux_kernel >= 4.14.313, < 4.15`
- `linux_kernel >= 4.19.281, < 4.20`
- `linux_kernel >= 5.4.241, < 5.5`
- `linux_kernel >= 5.10.178, < 5.11`
- `linux_kernel >= 5.15.107, < 5.16`
- `linux_kernel >= 6.1.24, < 6.2`
- `linux_kernel >= 6.2.11, < 6.6.31`
- `linux_kernel >= 6.7, < 6.8.10`
- `linux_kernel = 6.9`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.8.10`
