cbcvebase.
CVE-2024-26831
published 2024-04-17

CVE-2024-26831: In the Linux kernel, the following vulnerability has been resolved: net/handshake: Fix handshake_req_destroy_test1 Recently, handshake_req_destroy_test1…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Fix handshake_req_destroy_test1 Recently, handshake_req_destroy_test1 started failing: Expected handshake_req_destroy_test == req, but handshake_req_destroy_test == 0000000000000000 req == 0000000060f99b40 not ok 11 req_destroy works This is because "sock_release(sock)" was replaced with "fput(filp)" to address a memory leak. Note that sock_release() is synchronous but fput() usually delays the final close and clean-up. The delay is not consequential in the other cases that were changed but handshake_req_destroy_test1 is testing that handshake_req_cancel() followed by closing the file actually does call the ->hp_destroy method. Thus the PTR_EQ test at the end has to be sure that the final close is complete before it checks the pointer. We cannot use a completion here because if ->hp_destroy is never called (ie, there is an API bug) then the test will hang. Reported by: Guenter Roeck

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.7-1 (forky)linux 6.7.7-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 4a0f07d71b0483cc08c03cefa7c85749e187c214 < d74226e03df1bf19848f18344401f254345af912d74226e03df1bf19848f18344401f254345af912
linuxlinux>= 4a0f07d71b0483cc08c03cefa7c85749e187c214 < 7f97805b8df6e33850e225e6bd3ebd9e246920af7f97805b8df6e33850e225e6bd3ebd9e246920af
linuxlinux>= 4a0f07d71b0483cc08c03cefa7c85749e187c214 < 4e1d71cabb19ec2586827adfc60d68689c68c1944e1d71cabb19ec2586827adfc60d68689c68c194
linuxlinux>= 6.5.6 < 6.66.6
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 6.6 < 6.6.186.6.18
linuxlinux_kernel>= 6.7 < 6.7.66.7.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.