---
id: CVE-2024-44986
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: fix possible UAF in ip6_finish_output2()

  If skb_expand_head() returns NULL, skb has been freed
  and associated dst/idev could also have been freed.

  We need to ho…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: fix possible UAF in ip6_finish_output2()

  If skb_expand_head() returns NULL, skb has been freed
  and associated dst/idev could also have been freed.

  We need to ho…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: debian
product: debian_linux
affected:
  - debian_linux = 11.0
  - 'linux_kernel >= 5.4.137, < 5.4.289'
  - 'linux_kernel >= 5.10.55, < 5.10.233'
  - 'linux_kernel >= 5.13.7, < 5.15.166'
  - 'linux_kernel >= 5.16, < 6.1.107'
  - 'linux_kernel >= 6.2, < 6.6.48'
  - 'linux_kernel >= 6.7, < 6.10.7'
  - linux_kernel = 6.11
patched:
  - linux_kernel 6.10.7
published: '2024-09-04'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T13:17:38.417'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-44986'
references:
  - url: 'https://git.kernel.org/stable/c/1504108cb6020df7b1a31c9bb80fd587470aa448'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3574d28caf9a09756ae87ad1ea096c6f47b6101e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/56efc253196751ece1fc535a5b582be127b0578a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6ab6bf731354a6fdbaa617d1ec194960db61cf3b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ae8512e93f4ce47614ca89defaec1b93e00697b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/da273b377ae0d9bd255281ed3c2adb228321687b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e891b36de161fcd96f12ff83667473e5067b9037'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-09-04T20:20:05.005399Z'
ingestedAt: '2026-09-29T12:33:37.297Z'
epss: 0.00706
epssPercentile: 0.51498
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix possible UAF in ip6_finish_output2()

If skb_expand_head() returns NULL, skb has been freed
and associated dst/idev could also have been freed.

We need to hold rcu_read_lock() to make sure the dst and
associated idev are alive.

## Affected

- `debian_linux = 11.0`
- `linux_kernel >= 5.4.137, < 5.4.289`
- `linux_kernel >= 5.10.55, < 5.10.233`
- `linux_kernel >= 5.13.7, < 5.15.166`
- `linux_kernel >= 5.16, < 6.1.107`
- `linux_kernel >= 6.2, < 6.6.48`
- `linux_kernel >= 6.7, < 6.10.7`
- `linux_kernel = 6.11`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.10.7`
