Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-26642— netfilter: nf_tables: disallow anonymous set with timeout flag

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfilter:nf_tables:disallow存在带超时标志的匿名集。

CVSS 7.8 · High EPSS 0.27% · P17

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 761da2935d6e18d178582dbdf315a3a458555505< e4988d8415bd0294d6f9f4a1e7095f8b50a97ca9 affected
761da2935d6e18d178582dbdf315a3a458555505< e9a0d3f376eb356d54ffce36e7cc37514cbfbd6f affected
761da2935d6e18d178582dbdf315a3a458555505< fe40ffbca19dc70d7c6b1e3c77b9ccb404c57351 affected
761da2935d6e18d178582dbdf315a3a458555505< 7cdc1be24cc1bcd56a3e89ac4aef20e31ad09199 affected
761da2935d6e18d178582dbdf315a3a458555505< 72c1efe3f247a581667b7d368fff3bd9a03cd57a affected
761da2935d6e18d178582dbdf315a3a458555505< c0c2176d1814b92ea4c8e7eb7c9cd94cd99c1b12 affected
761da2935d6e18d178582dbdf315a3a458555505< 8e07c16695583a66e81f67ce4c46e94dece47ba7 affected
761da2935d6e18d178582dbdf315a3a458555505< 16603605b667b70da974bea8216c93e7db043bf1 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-26642

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nf_tables: disallow anonymous set with timeout flag
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout from userspace, reject this. Exception to this rule is NFT_SET_EVAL to ensure legacy meters still work.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfilter:nf_tables:disallow存在带超时标志的匿名集。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 761da2935d6e18d178582dbdf315a3a458555505 ~ e4988d8415bd0294d6f9f4a1e7095f8b50a97ca9 -
Linux Linux 4.1 -

II. Public POCs for CVE-2024-26642

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26642

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-26642 (1)

Mailing List Discussions for CVE-2024-26642 (2)

Other References for CVE-2024-26642 (7)

Same Patch Batch · Linux · 2024-03-21 · 3 CVEs total

CVE-2024-26643 7.8 HIGH netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
CVE-2023-52620 7.8 HIGH netfilter: nf_tables: disallow timeout for anonymous sets

IV. Related Vulnerabilities

V. Comments for CVE-2024-26642

No comments yet


Leave a comment