boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-36288MEDIUM
Linux Linux — SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  N  H    5.5   .0075   52.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    ab8466d4e26806a4ae82c282762c4545eecf45ef –  —
  Linux    6.9.3 –                                     —
TIMELINE
  Jun 21  Reserved by Linux
  Jun 21  Published (CNA: Linux)
  Aug 4   RESCORED — CVE-2024-36288 (Linux). CVSS 9.8 → 5.5 (NVD).
CWE-835 · CNA: Linux · CVSS v3.1 · 11 references · NVD status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory-access in range [0x04a2013400000008-0x04a201340000000f]

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 21, 2024ReservedReserved by Linux
June 21, 2024PublishedPublished (CNA: Linux)
August 4, 2026RESCOREDRESCORED — CVE-2024-36288 (Linux). CVSS 9.8 → 5.5 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinuxab8466d4e26806a4ae82c282762c4545eecf45ef
LinuxLinux6.9.3

Weaknesses

CWE-835

References (11)

Related

Authoritative record: CVE-2024-36288 at cve.org

Vendors: linux

Weaknesses: CWE-835

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-36288 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.