CVE-2024-26921Buffer Underflow in Linux

CWE-124Buffer Underflow45 documents8 sources
Severity
5.5MEDIUMNVD
OSV8.4OSV7.8OSV6.8OSV5.3
EPSS
0.1%
top 82.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: inet: inet_defrag: prevent sk release while still in use ip_local_out() and other functions can pass skb->sk as function argument. If the skb is a fragment and reassembly happens before such function call returns, the sk must not be released. This affects skb fragments reassembled via netfilter or similar modules, e.g. openvswitch or ct_act.c, when run as part of tx pipeline. Eric Dumazet made an initial analysis of this bu

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel4.15.4.285+6
Debianlinux/linux_kernel< 5.10.234-1+3
Ubuntulinux/linux_kernel< 5.4.0-193.213+14
CVEListV5linux/linux7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab1b6de5e6575b56502665c65cf93b0ae6aa0f51ab+7
debiandebian/linux< linux 6.1.85-1 (bookworm)

Patches

🔴Vulnerability Details

21
OSV
linux-fips vulnerabilities2025-04-09
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2025-04-09
OSV
Kernel Live Patch Security Notice2025-02-20
OSV
linux-azure, linux-azure-4.15 vulnerabilities2025-01-09
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2025-01-06

📋Vendor Advisories

22
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-269212025-04-17
Ubuntu
Linux kernel vulnerabilities2025-04-09
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-04-09
Ubuntu
Kernel Live Patch Security Notice2025-02-20
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-09

💬Community

1
Bugzilla
CVE-2024-26921 kernel: inet: inet_defrag: prevent sk release while still in use2024-04-18