CVE-2024-26581Use After Free in Linux

CWE-416Use After Free25 documents9 sources
Severity
7.8HIGHNVD
OSV7.5OSV7.0OSV6.8
EPSS
0.3%
top 47.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval elements that are not yet active.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages13 packages

NVDlinux/linux_kernel5.4.2625.4.269+5
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-177.197+4
CVEListV5linux/linux8284a79136c384059e85e278da2210b809730287c60d252949caf9aba537525195edae6bbabc35eb+9
debiandebian/linux< linux 6.1.82-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

10
OSV
Kernel Live Patch Security Notice2024-06-10
OSV
linux-azure-6.5 vulnerabilities2024-04-24
OSV
linux-azure, linux-lowlatency, linux-nvidia vulnerabilities2024-04-23
OSV
linux-lowlatency-hwe-6.5 vulnerabilities2024-04-22
OSV
linux, linux-aws, linux-aws-5.15, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.12024-04-19

📋Vendor Advisories

12
CISA ICS
Siemens SINEC OS2025-08-14
Ubuntu
Kernel Live Patch Security Notice2024-06-10
Ubuntu
Linux kernel (Azure) vulnerabilities2024-04-24
Ubuntu
Linux kernel vulnerabilities2024-04-23
Ubuntu
Linux kernel (Low Latency) vulnerabilities2024-04-22

💬Community

2
Bugzilla
CVE-2024-35800 kernel: efi: fix panic in kdump kernel2024-05-18
Bugzilla
CVE-2024-26581 kernel: nftables: nft_set_rbtree skip end interval element from gc2024-02-20
CVE-2024-26581 — Use After Free in Linux | cvebase