CVE-2024-26804 — Use After Free in Linux
Severity
5.3MEDIUMNVD
OSV7.8OSV7.0OSV6.5OSV5.5
EPSS
0.3%
top 42.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 4
Latest updateAug 14
Description
In the Linux kernel, the following vulnerability has been resolved:
net: ip_tunnel: prevent perpetual headroom growth
syzkaller triggered following kasan splat:
BUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170
Read of size 1 at addr ffff88812fb4000e by task syz-executor183/5191
[..]
kasan_report+0xda/0x110 mm/kasan/report.c:588
__skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170
skb_flow_dissect_flow_keys include/linux/skbuff.h:1514 [inl…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
▶CVEListV5linux/linux243aad830e8a4cdda261626fbaeddde16b08d04a — f81e94d2dcd2397137edcb8b85f4c5bed5d22383+8
Also affects: Debian Linux 10.0