cbcvebase.
CVE-2024-26597
published 2024-02-23

CVE-2024-26597: In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix global oob in rmnet_policy The variable rmnet_link_ops assign a…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix global oob in rmnet_policy The variable rmnet_link_ops assign a *bigger* maxtype which leads to a global out-of-bounds read when parsing the netlink attributes. See bug trace below: BUG: KASAN: global-out-of-bounds in validate_nla lib/nlattr.c:386 [inline] BUG: KASAN: global-out-of-bounds in __nla_validate_parse+0x24af/0x2750 lib/nlattr.c:600 Read of size 1 at addr ffffffff92c438d0 by task syz-executor.6/84207 CPU: 0 PID: 84207 Comm: syz-executor.6 Tainted: G N 6.1.0 #3 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x8b/0xb3 lib/dump_stack.c:106 print_address_description mm/kasan/report.c:284 [inline] print_report+0x172/0x475 mm/kasan/report.c:395 kasan_report+0xbb/0x1c0 mm/kasan/report.c:495 validate_nla lib/nlattr.c:386 [inline] __nla_validate_parse+0x24af/0x2750 lib/nlattr.c:600 __nla_parse+0x3e/0x50 lib/nlattr.c:697 nla_parse_nested_deprecated include/net/netlink.h:1248 [inline] __rtnl_newlink+0x50a/0x1880 net/core/rtnetlink.c:3485 rtnl_newlink+0x64/0xa0 net/core/rtnetlink.c:3594 rtnetlink_rcv_msg+0x43c/0xd70 net/core/rtnetlink.c:6091 netlink_rcv_skb+0x14f/0x410 net/netlink/af_netlink.c:2540 netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline] netlink_unicast+0x54e/0x800 net/netlink/af_netlink.c:1345 netlink_sendmsg+0x930/0xe50 net/netlink/af_netlink.c:1921 sock_sendmsg_nosec net/socket.c:714 [inline] sock_sendmsg+0x154/0x190 net/socket.c:734 ____sys_sendmsg+0x6df/0x840 net/socket.c:2482 ___sys_sendmsg+0x110/0x1b0 net/socket.c:2536 __sys_sendmsg+0xf3/0x1c0 net/socket.c:2565 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7fdcf2072359 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < 093dab655808207f7a9f54cf156240aeafc70590093dab655808207f7a9f54cf156240aeafc70590
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < 02467ab8b404d80429107588e0f3425cf5fcd2e502467ab8b404d80429107588e0f3425cf5fcd2e5
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < 2295c22348faf795e1ccdf618f6eb7afdb2f74472295c22348faf795e1ccdf618f6eb7afdb2f7447
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < 3b5254862258b595662a0ccca6e9eeb88d6e74683b5254862258b595662a0ccca6e9eeb88d6e7468
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < ee1dc3bf86f2df777038506b139371a9add02534ee1dc3bf86f2df777038506b139371a9add02534
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < c4734535034672f59f2652e1e0058c490da62a5cc4734535034672f59f2652e1e0058c490da62a5c
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < 17d06a5c44d8fd2e8e61bac295b09153496f87e117d06a5c44d8fd2e8e61bac295b09153496f87e1
linuxlinux>= 14452ca3b5ce304fb2fea96dbc9ca1e4e7978551 < b33fb5b801c6db408b774a68e7c8722796b59eccb33fb5b801c6db408b774a68e7c8722796b59ecc
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-176.1965.4.0-176.196
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.4.0-176.1965.4.0-176.196
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.17.0 < 4.19.3064.19.306
linuxlinux_kernel>= 4.20.0 < 5.4.2685.4.268
linuxlinux_kernel>= 5.11.0 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16.0 < 6.1.756.1.75

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.