CVE-2024-26634
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2024
Last modified:
10/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: fix removing a namespace with conflicting altnames<br />
<br />
Mark reports a BUG() when a net namespace is removed.<br />
<br />
kernel BUG at net/core/dev.c:11520!<br />
<br />
Physical interfaces moved outside of init_net get "refunded"<br />
to init_net when that namespace disappears. The main interface<br />
name may get overwritten in the process if it would have<br />
conflicted. We need to also discard all conflicting altnames.<br />
Recent fixes addressed ensuring that altnames get moved<br />
with the main interface, which surfaced this problem.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.60 (including) | 6.1.76 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.15 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.3 (excluding) |
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/8072699aa9e67d1727692cfb3c347263bb627fb9
- https://git.kernel.org/stable/c/a2232f29bf52c24f827865b3c90829c44b6c695b
- https://git.kernel.org/stable/c/d09486a04f5da0a812c26217213b89a3b1acf836
- https://git.kernel.org/stable/c/e855dded4b70d1975ee7b9fed0c700391e3c8ea6
- https://git.kernel.org/stable/c/8072699aa9e67d1727692cfb3c347263bb627fb9
- https://git.kernel.org/stable/c/a2232f29bf52c24f827865b3c90829c44b6c695b
- https://git.kernel.org/stable/c/d09486a04f5da0a812c26217213b89a3b1acf836
- https://git.kernel.org/stable/c/e855dded4b70d1975ee7b9fed0c700391e3c8ea6