cbcvebase.
CVE-2024-26679
published 2024-04-02

CVE-2024-26679: In the Linux kernel, the following vulnerability has been resolved: inet: read sk->sk_family once in inet_recv_error() inet_recv_error() is called without…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: inet: read sk->sk_family once in inet_recv_error() inet_recv_error() is called without holding the socket lock. IPv6 socket could mutate to IPv4 with IPV6_ADDRFORM socket option and trigger a KCSAN warning.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 3.17.7 < 3.183.18
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < caa064c3c2394d03e289ebd6b0be5102eb8a5b40caa064c3c2394d03e289ebd6b0be5102eb8a5b40
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < 5993f121fbc01dc2d734f0ff2628009b258fb1dd5993f121fbc01dc2d734f0ff2628009b258fb1dd
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < 88081ba415224cf413101def4343d660f56d082b88081ba415224cf413101def4343d660f56d082b
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < 3266e638ba5cc1165f5e6989eb8c0720f1cc4b413266e638ba5cc1165f5e6989eb8c0720f1cc4b41
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < 54538752216bf89ee88d47ad07802063a498c29954538752216bf89ee88d47ad07802063a498c299
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < 4a5e31bdd3c1702b520506d9cf8c41085f75c7f24a5e31bdd3c1702b520506d9cf8c41085f75c7f2
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < 307fa8a75ab7423fa5c73573ec3d192de5027830307fa8a75ab7423fa5c73573ec3d192de5027830
linuxlinux>= f4713a3dfad045d46afcb9c2a7d0bba288920ed4 < eef00a82c568944f113f2de738156ac591bbd5cdeef00a82c568944f113f2de738156ac591bbd5cd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 0 < 4.15.0-228.2404.15.0-228.240
linuxlinux_kernel>= 3.18 < 4.19.3074.19.307
linuxlinux_kernel>= 4.20 < 5.4.2695.4.269
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.