cbcvebase.
CVE-2024-26855
published 2024-04-17

CVE-2024-26855: In the Linux kernel, the following vulnerability has been resolved: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() The function…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() The function ice_bridge_setlink() may encounter a NULL pointer dereference if nlmsg_find_attr() returns NULL and br_spec is dereferenced subsequently in nla_for_each_nested(). To address this issue, add a check to ensure that br_spec is not NULL before proceeding with the nested attribute iteration.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < d9fefc51133107e59d192d773be86c1150cfeebbd9fefc51133107e59d192d773be86c1150cfeebb
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < 37fe99016b12d32100ce670216816dba6c48b30937fe99016b12d32100ce670216816dba6c48b309
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < 8d95465d9a424200485792858c5b3be54658ce198d95465d9a424200485792858c5b3be54658ce19
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < afdd29726a6de4ba27cd15590661424c888dc596afdd29726a6de4ba27cd15590661424c888dc596
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < 1a770927dc1d642b22417c3e668c871689fc58b31a770927dc1d642b22417c3e668c871689fc58b3
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < 0e296067ae0d74a10b4933601f9aa9f0ec8f157f0e296067ae0d74a10b4933601f9aa9f0ec8f157f
linuxlinux>= b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2 < 06e456a05d669ca30b224b8ed962421770c1496c06e456a05d669ca30b224b8ed962421770c1496c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.20 < 5.4.2725.4.272
linuxlinux_kernel>= 5.11 < 5.15.1525.15.152
linuxlinux_kernel>= 5.16 < 6.1.826.1.82
linuxlinux_kernel>= 5.5 < 5.10.2135.10.213
linuxlinux_kernel>= 6.2 < 6.6.226.6.22
linuxlinux_kernel>= 6.7 < 6.7.106.7.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.