CVE-2024-26882Improper Neutralization of Null Byte or NUL Character in Linux

Severity
7.8HIGHNVD
OSV7.0OSV6.5OSV5.5
EPSS
0.0%
top 89.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateJul 31

Description

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()") 1ca1ba465e55 ("geneve: make sure to pull inner header in geneve_rx()") We have to save skb->network_header in a temporary variable in order to be able to recompute the network_header pointer after a pskb_inet_may_pull() call. pskb_inet_may_pu

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages9 packages

Patches

🔴Vulnerability Details

24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-07-31
OSV
linux vulnerability2024-07-29
OSV
linux-raspi vulnerabilities2024-07-26
OSV
linux-aws, linux-aws-5.4, linux-iot vulnerabilities2024-07-23
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities2024-07-19

📋Vendor Advisories

25
Ubuntu
Linux kernel vulnerabilities2024-07-31
Ubuntu
Linux kernel vulnerability2024-07-29
Ubuntu
Linux kernel vulnerabilities2024-07-26
Ubuntu
Linux kernel vulnerabilities2024-07-23
Ubuntu
Linux kernel vulnerabilities2024-07-19

💬Community

1
Bugzilla
CVE-2024-26882 kernel: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()2024-04-17