cbcvebase.
CVE-2024-26882
published 2024-04-17

CVE-2024-26882: In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.83%
53.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()") 1ca1ba465e55 ("geneve: make sure to pull inner header in geneve_rx()") We have to save skb->network_header in a temporary variable in order to be able to recompute the network_header pointer after a pskb_inet_may_pull() call. pskb_inet_may_pull() makes sure the needed headers are in skb->head. syzbot reported: BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] BUG: KMSAN: uninit-value in IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline] BUG: KMSAN: uninit-value in ip_tunnel_rcv+0xed9/0x2ed0 net/ipv4/ip_tunnel.c:409 __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline] ip_tunnel_rcv+0xed9/0x2ed0 net/ipv4/ip_tunnel.c:409 __ipgre_rcv+0x9bc/0xbc0 net/ipv4/ip_gre.c:389 ipgre_rcv net/ipv4/ip_gre.c:411 [inline] gre_rcv+0x423/0x19f0 net/ipv4/ip_gre.c:447 gre_rcv+0x2a4/0x390 net/ipv4/gre_demux.c:163 ip_protocol_deliver_rcu+0x264/0x1300 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x2b8/0x440 net/ipv4/ip_input.c:233 NF_HOOK include/linux/netfilter.h:314 [inline] ip_local_deliver+0x21f/0x490 net/ipv4/ip_input.c:254 dst_input include/net/dst.h:461 [inline] ip_rcv_finish net/ipv4/ip_input.c:449 [inline] NF_HOOK include/linux/netfilter.h:314 [inline] ip_rcv+0x46f/0x760 net/ipv4/ip_input.c:569 __netif_receive_skb_one_core net/core/dev.c:5534 [inline] __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5648 netif_receive_skb_internal net/core/dev.c:5734 [inline] netif_receive_skb+0x58/0x660 net/core/dev.c:5793 tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1556 tun_get_user+0x53b9/0x66e0 drive

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < ec6bb01e02cbd47781dd90775b631a1dc4bd9d2bec6bb01e02cbd47781dd90775b631a1dc4bd9d2b
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < 77fd5294ea09b21f6772ac954a121b87323cec8077fd5294ea09b21f6772ac954a121b87323cec80
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < 5c03387021cfa3336b97e0dcba38029917a8af2a5c03387021cfa3336b97e0dcba38029917a8af2a
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < 60044ab84836359534bd7153b92e9c1584140e4a60044ab84836359534bd7153b92e9c1584140e4a
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < c4c857723b37c20651300b3de4ff25059848b4b0c4c857723b37c20651300b3de4ff25059848b4b0
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < f6723d8dbfdc10c784a56748f86a9a3cd410dbd5f6723d8dbfdc10c784a56748f86a9a3cd410dbd5
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < ca914f1cdee8a85799942c9b0ce5015bbd6844e1ca914f1cdee8a85799942c9b0ce5015bbd6844e1
linuxlinux>= c54419321455631079c7d6e60bc732dd0c5914c5 < b0ec2abf98267f14d032102551581c833b0659d3b0ec2abf98267f14d032102551581c833b0659d3
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 0 < 3.13.0-198.2493.13.0-198.249
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 3.10 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.