Answer in brief
CVE-2024-46855 records a Unknown severity vulnerability in netfilter: nft_socket: fix sk refcount leaks. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-46855 records a Unknown severity vulnerability in netfilter: nft_socket: fix sk refcount leaks. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 5.3 | Not reported |
| Linux/Linuxgeneric | >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <076d281e90aaf4192799ecb9a1ed82321e133ecd || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <6572440f78b724c46070841a68254ebc534cde24 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <ddc7c423c4a5386bf865474c694b48178efd311a || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <33c2258bf8cb17fba9e58b111d4c4f4cf43a4896 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <83e6fb59040e8964888afcaa5612cc1243736715 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <1f68e097e20d3c695281a9c6433acc37be47fe11 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <8b26ff7af8c32cb4148b3e147c52f9e4c695209c || 6934809432d23e9e0081f82d882b8fc765deeb4a || f63432cd1bb224f61216e4a4726ff29ddffbed98 || >=4.19.76 <4.20 || >=5.2.18 <5.3 | 076d281e90aaf4192799ecb9a1ed82321e133ecd, 6572440f78b724c46070841a68254ebc534cde24, ddc7c423c4a5386bf865474c694b48178efd311a, 33c2258bf8cb17fba9e58b111d4c4f4cf43a4896, 83e6fb59040e8964888afcaa5612cc1243736715, 1f68e097e20d3c695281a9c6433acc37be47fe11, 8b26ff7af8c32cb4148b3e147c52f9e4c695209c, 4.20, 5.3 |
Published upstream
Sep 27, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: fix sk refcount leaks We must put 'sk' reference before returning.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 5.3 | Not reported |
| Linux/Linuxgeneric | >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <076d281e90aaf4192799ecb9a1ed82321e133ecd || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <6572440f78b724c46070841a68254ebc534cde24 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <ddc7c423c4a5386bf865474c694b48178efd311a || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <33c2258bf8cb17fba9e58b111d4c4f4cf43a4896 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <83e6fb59040e8964888afcaa5612cc1243736715 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <1f68e097e20d3c695281a9c6433acc37be47fe11 || >=039b1f4f24ecc8493b6bb9d70b4b78750d1b35c2 <8b26ff7af8c32cb4148b3e147c52f9e4c695209c || 6934809432d23e9e0081f82d882b8fc765deeb4a || f63432cd1bb224f61216e4a4726ff29ddffbed98 || >=4.19.76 <4.20 || >=5.2.18 <5.3 | 076d281e90aaf4192799ecb9a1ed82321e133ecd, 6572440f78b724c46070841a68254ebc534cde24, ddc7c423c4a5386bf865474c694b48178efd311a, 33c2258bf8cb17fba9e58b111d4c4f4cf43a4896, 83e6fb59040e8964888afcaa5612cc1243736715, 1f68e097e20d3c695281a9c6433acc37be47fe11, 8b26ff7af8c32cb4148b3e147c52f9e4c695209c, 4.20, 5.3 |
Published upstream
Sep 27, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: fix sk refcount leaks We must put 'sk' reference before returning.
Quoted source text, attributed separately from HOL analysis.