LiveActive security incident?Get immediate response
CVE Record

CVE-2024-27390: ipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down()

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down() As discussed in the past (commit 2d3916f31891 ("ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()")) I think the synchronize_net() call in ipv6_mc_down() is not needed. Under load, synchronize_net() can last between 200 usec and 5 ms. KASAN seems to agree as well.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue concerns an apparently unnecessary synchronization pause while shutting down IPv6 multicast handling. Under load, the pause can last 200 microseconds to 5 milliseconds. The supplied sources do not describe a demonstrated security impact, severity score, crash, data exposure, or privilege gain.

Executive priority

Treat this as a routine, evidence-limited kernel maintenance item rather than an emergency. Include it in normal patch cycles, with earlier attention for latency-sensitive or heavily loaded IPv6 multicast environments. Escalate if vendor guidance identifies a concrete security impact or exploitation evidence.

Technical view

The kernel fix removes one synchronize_net() barrier from ipv6_mc_down(). The record references earlier IPv6 multicast packet-drop work and says KASAN testing supported removal. No CWE, CVSS vector, attack prerequisites, or concrete confidentiality, integrity, or availability impact is provided, limiting technical risk assessment.

Likely exposure

The bundle identifies Linux kernel versions 5.13, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, and 6.9 as affected; it also contains an unexplained version value of 0. Exposure is most relevant where those kernels perform IPv6 multicast operations under load. Distribution backports may change status.

Exploitation context

CISA KEV status is false, and the supplied sources provide no evidence of active exploitation, public exploit code, or a practical attack path. They describe synchronization latency under load rather than an established security consequence. Absence from this bundle does not prove exploitation is impossible.

Researcher notes

The record is unusually sparse and resembles a performance or correctness change: it quantifies barrier latency but does not establish attacker control or security impact. The flattened version data is ambiguous, including repeated commit identifiers and a version value of 0. Review the CVE JSON and stable commit metadata before making exact range claims.

Mitigation direction

  • Identify deployed kernel versions and distribution-specific package revisions.
  • Check Linux stable and distribution guidance for the applicable backported fix.
  • Upgrade to a supported kernel containing the relevant stable fix after compatibility testing.
  • Prioritize heavily loaded systems using IPv6 multicast while impact remains uncertain.

Validation and detection

  • Record uname and package-manager kernel versions for each system.
  • Map distribution package revisions to the referenced upstream stable commits.
  • Confirm the updated kernel is active after maintenance and reboot.
  • Monitor IPv6 multicast behavior and latency under representative load.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-27390 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux94d6a071ab2f26eb18a83109940db0cec19552fd, f185de28d9ae6c978135993769352e523ee8df06, f185de28d9ae6c978135993769352e523ee8df06, f185de28d9ae6c978135993769352e523ee8df06, f185de28d9ae6c978135993769352e523ee8df06, f185de28d9ae6c978135993769352e523ee8df06, f185de28d9ae6c978135993769352e523ee8df06unaffected
LinuxLinux5.13, 0, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, 6.9affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.