cbcvebase.
CVE-2024-26951
published 2024-05-01

CVE-2024-26951: In the Linux kernel, the following vulnerability has been resolved: wireguard: netlink: check for dangling peer via is_dead instead of empty list If all peers…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wireguard: netlink: check for dangling peer via is_dead instead of empty list If all peers are removed via wg_peer_remove_all(), rather than setting peer_list to empty, the peer is added to a temporary list with a head on the stack of wg_peer_remove_all(). If a netlink dump is resumed and the cursored peer is one that has been removed via wg_peer_remove_all(), it will iterate from that peer and then attempt to dump freed peers. Fix this by instead checking peer->is_dead, which was explictly created for this purpose. Also move up the device_update_lock lockdep assertion, since reading is_dead relies on that. It can be reproduced by a small script like: echo "Setting config..." ip link add dev wg0 type wireguard wg setconf wg0 /big-config ( while true; do echo "Showing config..." wg showconf wg0 > /dev/null done ) & sleep 4 wg setconf wg0 dump_stack_lvl+0x47/0x70 print_address_description.constprop.0+0x2c/0x380 print_report+0xab/0x250 kasan_report+0xba/0xf0 __lock_acquire+0x182a/0x1b20 lock_acquire+0x191/0x4b0 down_read+0x80/0x440 get_peer+0x140/0xcb0 wg_get_device_dump+0x471/0x1130

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < f52be46e3e6ecefc2539119784324f0cbc09620af52be46e3e6ecefc2539119784324f0cbc09620a
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 710a177f347282eea162aec8712beb1f42d5ad87710a177f347282eea162aec8712beb1f42d5ad87
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < b7cea3a9af0853fdbb1b16633a458f991dde6aacb7cea3a9af0853fdbb1b16633a458f991dde6aac
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 13d107794304306164481d31ce33f8fdb25a9c0413d107794304306164481d31ce33f8fdb25a9c04
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 7bedfe4cfa38771840a355970e4437cd52d4046b7bedfe4cfa38771840a355970e4437cd52d4046b
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 302b2dfc013baca3dea7ceda383930d9297d231d302b2dfc013baca3dea7ceda383930d9297d231d
linuxlinux>= e7096c131e5161fa3b8e52a650d7719d2857adfd < 55b6c738673871c9b0edae05d0c97995c1ff08c455b6c738673871c9b0edae05d0c97995c1ff08c4
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 5.6 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8MEDIUM
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.