CVE-2024-26663NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
OSV7.0OSV6.5
EPSS
0.0%
top 94.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: tipc: Check the bearer type before calling tipc_udp_nl_bearer_add() syzbot reported the following general protection fault [1]: general protection fault, probably for non-canonical address 0xdffffc0000000010: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087] ... RIP: 0010:tipc_udp_is_known_peer+0x9c/0x250 net/tipc/udp_media.c:291 ... Call Trace: tipc_udp_nl_bearer_add+0x212/0x

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel4.94.19.307+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-181.201+2
CVEListV5linux/linuxef20cd4dd1633987bcf46ac34ace2c8af212361f24ec8f0da93b8a9fba11600be8a90f0d73fb46f1+8
debiandebian/linux< linux 6.1.82-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

17
OSV
linux-azure vulnerabilities2025-02-03
OSV
linux-azure, linux-azure-4.15 vulnerabilities2025-01-30
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2025-01-28
OSV
linux-oem-6.5 vulnerabilities2024-08-02
OSV
linux-aws-6.5, linux-lowlatency-hwe-6.5, linux-oracle-6.5, linux-starfive-6.5 vulnerabilities2024-07-19

📋Vendor Advisories

18
CISA ICS
Siemens SINEC OS2025-08-14
Ubuntu
Linux kernel (Azure) vulnerabilities2025-02-03
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-30
Ubuntu
Linux kernel vulnerabilities2025-01-28
Ubuntu
Linux kernel vulnerabilities2024-08-02

💬Community

1
Bugzilla
CVE-2024-26663 kernel: tipc: Check the bearer type before calling tipc_udp_nl_bearer_add()2024-04-02