cbcvebase.
CVE-2024-26677
published 2024-04-02

CVE-2024-26677: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix delayed ACKs to not set the reference serial number Fix the construction of…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix delayed ACKs to not set the reference serial number Fix the construction of delayed ACKs to not set the reference serial number as they can't be used as an RTT reference.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.7-1 (forky)linux 6.7.7-1 (forky)
linuxlinux
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < 200cb50b9e154434470c8969d32474d38475acc2200cb50b9e154434470c8969d32474d38475acc2
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < 63719f490e6a89896e9a463d2b45e8203eab23ae63719f490e6a89896e9a463d2b45e8203eab23ae
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < e7870cf13d20f56bfc19f9c3e89707c69cf104efe7870cf13d20f56bfc19f9c3e89707c69cf104ef
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-196.2165.4.0-196.216
linuxlinux_kernel>= 0 < 5.15.0-122.1325.15.0-122.132
linuxlinux_kernel>= 0 < 4.4.0-259.2934.4.0-259.293
linuxlinux_kernel>= 0 < 4.15.0-229.2414.15.0-229.241
linuxlinux_kernel>= 2.6.22 < 6.6.176.6.17
linuxlinux_kernel>= 6.7 < 6.7.56.7.5
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.