cbcvebase.
CVE-2024-26739
published 2024-04-03

CVE-2024-26739: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcode to SHOT. If we have called tcf_mirred_forward(), however, the skb is out of our hands and returning SHOT will lead to UaF. Move the retval override to the error path which actually need it.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= e5cf1baf92cb785b90390db1c624948e70c8b8bd < 0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd
linuxlinux>= e5cf1baf92cb785b90390db1c624948e70c8b8bd < 9d3ef89b6a5e9f2e940de2cef3d543be0be8dec59d3ef89b6a5e9f2e940de2cef3d543be0be8dec5
linuxlinux>= e5cf1baf92cb785b90390db1c624948e70c8b8bd < e873e8f7d03a2ee5b77fb1a305c782fed98e2754e873e8f7d03a2ee5b77fb1a305c782fed98e2754
linuxlinux>= e5cf1baf92cb785b90390db1c624948e70c8b8bd < 28cdbbd38a4413b8eff53399b3f872fd4e80db9d28cdbbd38a4413b8eff53399b3f872fd4e80db9d
linuxlinux>= e5cf1baf92cb785b90390db1c624948e70c8b8bd < f4e294bbdca8ac8757db436fc82214f3882fc7e7f4e294bbdca8ac8757db436fc82214f3882fc7e7
linuxlinux>= e5cf1baf92cb785b90390db1c624948e70c8b8bd < 166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 4.19 < 5.10.2385.10.238
linuxlinux_kernel>= 5.11 < 5.15.1825.15.182
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 6.2 < 6.6.196.6.19
linuxlinux_kernel>= 6.7 < 6.7.76.7.7

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.