CVE-2024-26634

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2024
Last modified:
10/03/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: fix removing a namespace with conflicting altnames<br /> <br /> Mark reports a BUG() when a net namespace is removed.<br /> <br /> kernel BUG at net/core/dev.c:11520!<br /> <br /> Physical interfaces moved outside of init_net get "refunded"<br /> to init_net when that namespace disappears. The main interface<br /> name may get overwritten in the process if it would have<br /> conflicted. We need to also discard all conflicting altnames.<br /> Recent fixes addressed ensuring that altnames get moved<br /> with the main interface, which surfaced this problem.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.60 (including) 6.1.76 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6 (including) 6.6.15 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.3 (excluding)
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*