cbcvebase.
CVE-2024-26673
published 2024-04-02

CVE-2024-26673: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - Disallow…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - Disallow families other than NFPROTO_{IPV4,IPV6,INET}. - Disallow layer 4 protocol with no ports, since destination port is a mandatory attribute for this object.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < f549f340c91f08b938d60266e792ff7748dae483f549f340c91f08b938d60266e792ff7748dae483
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < 65ee90efc928410c6f73b3d2e0afdd762652c09d65ee90efc928410c6f73b3d2e0afdd762652c09d
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < b775ced05489f4b77a35fe203e9aeb22f428e38fb775ced05489f4b77a35fe203e9aeb22f428e38f
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < 0f501dae16b7099e69ee9b0d5c70b8f40fd30e980f501dae16b7099e69ee9b0d5c70b8f40fd30e98
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < cfe3550ea5df292c9e2d608e8c4560032391847ecfe3550ea5df292c9e2d608e8c4560032391847e
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < 38cc1605338d99205a263707f4dde76408d3e0e838cc1605338d99205a263707f4dde76408d3e0e8
linuxlinux>= 857b46027d6f91150797295752581b7155b9d0e1 < 8059918a1377f2f1fff06af4f5a4ed3d5acd6bc48059918a1377f2f1fff06af4f5a4ed3d5acd6bc4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.776.1.77
linuxlinux_kernel>= 5.3 < 5.4.2695.4.269
linuxlinux_kernel>= 5.5 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.166.6.16
linuxlinux_kernel>= 6.7 < 6.7.46.7.4

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.5HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.