CVE-2024-26635Missing Initialization of Resource in Linux

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.0%
top 98.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below. [0] llc supports ETH_P_802_2 (0x0004) and used to support ETH_P_TR_802_2 (0x0011), and syzbot abused the latter to trigger the bug. write$tun(r0, &(0x7f0000000040)={@val={0x0, 0x11}, @val, @mpls={[], @llc={@snap={0xaa, 0x1, ')', "90e5dd"}}}}, 0x16) llc_conn_handler() initialises local variables {saddr,daddr}.mac based on skb in llc_pdu_decode_s

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel3.54.19.307+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-181.201+3
CVEListV5linux/linux211ed865108e24697b44bee5daac502ee6bdd4a4165ad1e22779685c3ed3dd349c6c4c632309cc62+8
debiandebian/linux< linux 6.1.76-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

16
OSV
linux-intel-iotg-5.15 vulnerabilities2024-06-11
OSV
linux-intel-iotg vulnerabilities2024-05-28
OSV
linux-aws-hwe vulnerabilities2024-05-23
OSV
linux-gcp vulnerabilities2024-05-21
OSV
linux-aws, linux-aws-5.15 vulnerabilities2024-05-20

📋Vendor Advisories

16
CISA ICS
Siemens SINEC OS2025-08-14
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-06-11
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-05-28
Ubuntu
Linux kernel (HWE) vulnerabilities2024-05-23
Ubuntu
Linux kernel (GCP) vulnerabilities2024-05-21

💬Community

1
Bugzilla
CVE-2024-26635 kernel: llc: Drop support for ETH_P_TR_802_2.2024-03-18