CVE-2024-26849
published 2024-04-17CVE-2024-26849: In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
netlink: add nla be16/32 types to minlen array
BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline]
BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline]
BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline]
BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631
nla_validate_range_unsigned lib/nlattr.c:222 [inline]
nla_validate_int_range lib/nlattr.c:336 [inline]
validate_nla lib/nlattr.c:575 [inline]
...
The message in question matches this policy:
[NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255),
but because NLA_BE32 size in minlen array is 0, the validation
code will read past the malformed (too small) attribute.
Note: Other attributes, e.g. BITFIELD32, SINT, UINT.. are also missing:
those likely should be added too.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.82-1 (bookworm) | linux 6.1.82-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 24ea1c8abaae6541ad95912422a9af4fb858428d < 000a68159c0326b46c42ec712ab98793e7e625a7 | 000a68159c0326b46c42ec712ab98793e7e625a7 |
| linux | linux | >= cbfac0add2afe8960a09806012313765a2179423 < 80b40f9cb87f3bf5877dfb852765cf92bc03ca77 | 80b40f9cb87f3bf5877dfb852765cf92bc03ca77 |
| linux | linux | >= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < 0ac219c4c3ab253f3981f346903458d20bacab32 | 0ac219c4c3ab253f3981f346903458d20bacab32 |
| linux | linux | >= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < a2ab028151841cd833cb53eb99427e0cc990112d | a2ab028151841cd833cb53eb99427e0cc990112d |
| linux | linux | >= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < 7a9d14c63b35f89563c5ecbadf918ad64979712d | 7a9d14c63b35f89563c5ecbadf918ad64979712d |
| linux | linux | >= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < 9a0d18853c280f6a0ee99f91619f2442a17a323a | 9a0d18853c280f6a0ee99f91619f2442a17a323a |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.82-1 | 6.1.82-1 |
| linux | linux_kernel | >= 0 < 6.7.9-1 | 6.7.9-1 |
| linux | linux_kernel | >= 0 < 6.7.9-1 | 6.7.9-1 |
| linux | linux_kernel | >= 6.1 < 6.1.81 | 6.1.81 |
| linux | linux_kernel | >= 6.2 < 6.6.21 | 6.6.21 |
| linux | linux_kernel | >= 6.7 < 6.7.9 | 6.7.9 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vx2-7qpg-xf7m: In the Linux kernel, the following vulnerability has been resolved:
netlink: add nla be16/32 types to minlen array
BUG: KMSAN: uninit-value in nla_v
ghsa_unreviewed·2024-04-17
CVE-2024-26849 [MEDIUM] CWE-908 GHSA-9vx2-7qpg-xf7m: In the Linux kernel, the following vulnerability has been resolved:
netlink: add nla be16/32 types to minlen array
BUG: KMSAN: uninit-value in nla_v
In the Linux kernel, the following vulnerability has been resolved:
netlink: add nla be16/32 types to minlen array
BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline]
BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline]
BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline]
BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631
nla_validate_range_unsigned lib/nlattr.c:222 [inline]
nla_validate_int_range lib/nlattr.c:336 [inline]
validate_nla lib/nlattr.c:575 [inline]
...
The message in question matches this policy:
[NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255),
but because NLA_BE32 size in minlen array is 0, the validation
code will read past the malformed (too small) attribute.
Note: Other
OSV
CVE-2024-26849: In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_val
osv·2024-04-17·CVSS 5.5
CVE-2024-26849 [MEDIUM] CVE-2024-26849: In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_val
In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline] BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline] BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631 nla_validate_range_unsigned lib/nlattr.c:222 [inline] nla_validate_int_range lib/nlattr.c:336 [inline] validate_nla lib/nlattr.c:575 [inline] ... The message in question matches this policy: [NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255), but because NLA_BE32 size in minlen array is 0, the validation code will read past the malformed (too small) attribute. Note: Other attri
Red Hat
kernel: netlink: add nla be16/32 types to minlen array
vendor_redhat·2024-04-17·CVSS 5.5
CVE-2024-26849 [MEDIUM] kernel: netlink: add nla be16/32 types to minlen array
kernel: netlink: add nla be16/32 types to minlen array
In the Linux kernel, the following vulnerability has been resolved:
netlink: add nla be16/32 types to minlen array
BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline]
BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline]
BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline]
BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631
nla_validate_range_unsigned lib/nlattr.c:222 [inline]
nla_validate_int_range lib/nlattr.c:336 [inline]
validate_nla lib/nlattr.c:575 [inline]
...
The message in question matches this policy:
[NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255),
but because NLA_BE32 size in minlen array is 0, the validation
code will read pas
Debian
CVE-2024-26849: linux - In the Linux kernel, the following vulnerability has been resolved: netlink: ad...
vendor_debian·2024·CVSS 5.5
CVE-2024-26849 [MEDIUM] CVE-2024-26849: linux - In the Linux kernel, the following vulnerability has been resolved: netlink: ad...
In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline] BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline] BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631 nla_validate_range_unsigned lib/nlattr.c:222 [inline] nla_validate_int_range lib/nlattr.c:336 [inline] validate_nla lib/nlattr.c:575 [inline] ... The message in question matches this policy: [NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255), but because NLA_BE32 size in minlen array is 0, the validation code will read past the malformed (too small) attribute. Note: Other attri
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/000a68159c0326b46c42ec712ab98793e7e625a7https://git.kernel.org/stable/c/0ac219c4c3ab253f3981f346903458d20bacab32https://git.kernel.org/stable/c/7a9d14c63b35f89563c5ecbadf918ad64979712dhttps://git.kernel.org/stable/c/80b40f9cb87f3bf5877dfb852765cf92bc03ca77https://git.kernel.org/stable/c/9a0d18853c280f6a0ee99f91619f2442a17a323ahttps://git.kernel.org/stable/c/a2ab028151841cd833cb53eb99427e0cc990112dhttps://git.kernel.org/stable/c/0ac219c4c3ab253f3981f346903458d20bacab32https://git.kernel.org/stable/c/7a9d14c63b35f89563c5ecbadf918ad64979712dhttps://git.kernel.org/stable/c/9a0d18853c280f6a0ee99f91619f2442a17a323ahttps://git.kernel.org/stable/c/a2ab028151841cd833cb53eb99427e0cc990112d
2024-04-17
Published