CVE-2024-26609: netfilter: nf_tables: reject QUEUE/DROP verdict parameters
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftables: reject QUEUE/DROP verdict parameters
The Linux kernel CVE team has assigned CVE-2024-26609 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/20240229155245.1571576-41-lee@kernel.org/T
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a use-after-free error related to rejecting QUEUE/DROP verdict parameters. A local attacker could exploit this vulnerability to cause a denial of service.
— IBM
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26609?
CVE-2024-26609 is classified with a high severity due to its potential impact on network filtering within the Linux kernel.
What are the affected Linux kernel versions for CVE-2024-26609?
CVE-2024-26609 affects Linux kernel versions up to 4.19.307, 5.4.269, 5.10.210, 5.15.149, 6.1.76, 6.6.15, 6.7.3, and 6.8.
How do I fix CVE-2024-26609?
To mitigate CVE-2024-26609, update your Linux kernel to a version later than the specified affected versions.
What components are involved in CVE-2024-26609?
CVE-2024-26609 involves the netfilter component of the Linux kernel, specifically regarding QUEUE and DROP verdict parameters.
Is CVE-2024-26609 related to Red Hat distributions?
Yes, CVE-2024-26609 is specifically acknowledged in Red Hat's advisory related to their kernel packages.