Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-26809— netfilter: nft_set_pipapo: release elements in clone only from destroy path

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 netfilter nft_set_pipapo 中存在安全问题。

CVSS 7.8 · High EPSS 0.29% · P22

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux 4a6430b99f67842617c7208ca55a411e903ba03a< b36b83297ff4910dfc8705402c8abffd4bbf8144 affected
5ccecafc728b0df48263d5ac198220bcd79830bc< 362508506bf545e9ce18c72a2c48dcbfb891ab9c affected
9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e< 5ad233dc731ab64cdc47b84a5c1f78fff6c024af affected
9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e< ff90050771412b91e928093ccd8736ae680063c2 affected
9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e< 821e28d5b506e6a73ccc367ff792bd894050d48b affected
9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e< 9384b4d85c46ce839f51af01374062ce6318b2f2 affected
9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e< b0e256f3dd2ba6532f37c5c22e07cb07a36031ee affected
d2b18d110685ce46ca1633b8ec586c685e243a51 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-26809

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nft_set_pipapo: release elements in clone only from destroy path
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: release elements in clone only from destroy path Clone already always provides a current view of the lookup table, use it to destroy the set, otherwise it is possible to destroy elements twice. This fix requires: 212ed75dc5fb ("netfilter: nf_tables: integrate pipapo into commit protocol") which came after: 9827a0e6e23b ("netfilter: nft_set_pipapo: release elements in clone from abort path").
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 netfilter nft_set_pipapo 中存在安全问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 4a6430b99f67842617c7208ca55a411e903ba03a ~ b36b83297ff4910dfc8705402c8abffd4bbf8144 -
Linux Linux 5.19 -

II. Public POCs for CVE-2024-26809

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26809

登录查看更多情报信息。

Mailing List Discussions for CVE-2024-26809 (1)

Other References for CVE-2024-26809 (6)

Same Patch Batch · Linux · 2024-04-04 · 32 CVEs total

CVE-2024-26782 9.8 CRITICAL mptcp: fix double-free on socket dismantle
CVE-2024-26800 9.8 CRITICAL tls: fix use-after-free on failed backlog decryption
CVE-2024-26801 8.8 HIGH Bluetooth: Avoid potential use-after-free in hci_error_reset
CVE-2024-26792 7.8 HIGH btrfs: fix double free of anonymous device after snapshot creation failure
CVE-2024-26808 7.8 HIGH netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain
CVE-2024-26807 7.8 HIGH spi: cadence-qspi: fix pointer reference in runtime PM hooks
CVE-2024-26804 7.8 HIGH net: ip_tunnel: prevent perpetual headroom growth
CVE-2024-26802 7.8 HIGH stmmac: Clear variable when destroying workqueue
CVE-2024-26797 7.8 HIGH drm/amd/display: Prevent potential buffer overflow in map_hw_resources
CVE-2024-26795 7.8 HIGH riscv: Sparse-Memory/vmemmap out-of-bounds fix
CVE-2024-26793 7.8 HIGH gtp: fix use-after-free and null-ptr-deref in gtp_newlink()
CVE-2024-26789 7.8 HIGH crypto: arm64/neonbs - fix out-of-bounds access on short input
CVE-2024-26786 7.8 HIGH iommufd: Fix iopt_access_list_id overwrite bug
CVE-2024-26799 7.0 HIGH ASoC: qcom: Fix uninitialized pointer dmactl
CVE-2024-26746 dmaengine: idxd: Ensure safe user copy of completion record
CVE-2024-26788 dmaengine: fsl-qdma: init irq after reg initialization
CVE-2024-26750 af_unix: Drop oob_skb ref before purging queue in GC.
CVE-2024-26806 spi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks
CVE-2024-26805 netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter
CVE-2024-26780 af_unix: Fix task hung while purging oob_skb in GC.

Showing top 20 of 32 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26809

No comments yet


Leave a comment