cbcvebase.
CVE-2024-26849
published 2024-04-17

CVE-2024-26849: In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline] BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline] BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631 nla_validate_range_unsigned lib/nlattr.c:222 [inline] nla_validate_int_range lib/nlattr.c:336 [inline] validate_nla lib/nlattr.c:575 [inline] ... The message in question matches this policy: [NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255), but because NLA_BE32 size in minlen array is 0, the validation code will read past the malformed (too small) attribute. Note: Other attributes, e.g. BITFIELD32, SINT, UINT.. are also missing: those likely should be added too.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 24ea1c8abaae6541ad95912422a9af4fb858428d < 000a68159c0326b46c42ec712ab98793e7e625a7000a68159c0326b46c42ec712ab98793e7e625a7
linuxlinux>= cbfac0add2afe8960a09806012313765a2179423 < 80b40f9cb87f3bf5877dfb852765cf92bc03ca7780b40f9cb87f3bf5877dfb852765cf92bc03ca77
linuxlinux>= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < 0ac219c4c3ab253f3981f346903458d20bacab320ac219c4c3ab253f3981f346903458d20bacab32
linuxlinux>= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < a2ab028151841cd833cb53eb99427e0cc990112da2ab028151841cd833cb53eb99427e0cc990112d
linuxlinux>= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < 7a9d14c63b35f89563c5ecbadf918ad64979712d7a9d14c63b35f89563c5ecbadf918ad64979712d
linuxlinux>= ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f < 9a0d18853c280f6a0ee99f91619f2442a17a323a9a0d18853c280f6a0ee99f91619f2442a17a323a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 6.1 < 6.1.816.1.81
linuxlinux_kernel>= 6.2 < 6.6.216.6.21
linuxlinux_kernel>= 6.7 < 6.7.96.7.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.