cbcvebase.
CVE-2024-26668
published 2024-04-02

CVE-2024-26668: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: reject configurations that cause integer overflow Reject bogus…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: reject configurations that cause integer overflow Reject bogus configs where internal token counter wraps around. This only occurs with very very large requests, such as 17gbyte/s. Its better to reject this rather than having incorrect ratelimit.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= d2168e849ebf617b2b7feae44c0c0baf739cb610 < 79d4efd75e7dbecd855a3b8a63e65f7265f466e179d4efd75e7dbecd855a3b8a63e65f7265f466e1
linuxlinux>= d2168e849ebf617b2b7feae44c0c0baf739cb610 < bc6e242bb74e2ae616bfd2b250682b738e781c9bbc6e242bb74e2ae616bfd2b250682b738e781c9b
linuxlinux>= d2168e849ebf617b2b7feae44c0c0baf739cb610 < 9882495d02ecc490604f747437a40626dc9160d09882495d02ecc490604f747437a40626dc9160d0
linuxlinux>= d2168e849ebf617b2b7feae44c0c0baf739cb610 < 00c2c29aa36d1d1827c51a3720e9f893a22c7c6a00c2c29aa36d1d1827c51a3720e9f893a22c7c6a
linuxlinux>= d2168e849ebf617b2b7feae44c0c0baf739cb610 < c9d9eb9c53d37cdebbad56b91e40baf42d5a97aac9d9eb9c53d37cdebbad56b91e40baf42d5a97aa
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 4.3 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.766.1.76
linuxlinux_kernel>= 6.2 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.