PT-2024-1992 · Linux+10 · Linux Kernel+10

Orel Hagag

·

Published

2024-01-18

·

Updated

2025-09-29

·

CVE-2024-26586

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a stack corruption vulnerability in the Linux kernel, specifically in the mlxsw sp acl tcam module. This vulnerability can occur when more than 16 ACLs are required in a group, causing a kernel panic due to stack corruption. The vulnerability is fixed by limiting the maximum ACL group size to the minimum between what the firmware reports and the maximum ACLs that fit in the PAGT register. A test case has been added to ensure the machine does not crash when this condition is hit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2394
ALSA-2024:5101
ALSA-2024:5102
ALSA-2024_2394
ALSA-2025_16880
ALT-PU-2024-14046
ALT-PU-2024-17576
ALT-PU-2024-3291
ALT-PU-2024-4623
ALT-PU-2024-6818
BDU:2024-01840
CESA-2024_5101
CESA-2024_5102
CVE-2024-26586
DLA-3841-1
DSA-5658-1
INFSA-2024_2394
INFSA-2024_5101
INFSA-2024_5102
OESA-2024-2029
OESA-2024-2030
OESA-2024-2031
OPENSUSE-SU-2024_0857-1
OPENSUSE-SU-2024_0858-1
RHSA-2024:1881
RHSA-2024:1882
RHSA-2024:2006
RHSA-2024:2008
RHSA-2024:2394
RHSA-2024:2582
RHSA-2024:2585
RHSA-2024:2674
RHSA-2024:3414
RHSA-2024:3421
RHSA-2024:3810
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024_2394
RHSA-2024_5101
RHSA-2024_5102
RLSA-2024:5101
RLSA-2024:5102
RXSA-2024:5101
SUSE-SU-2024:0855-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0858-1
SUSE-SU-2024:0900-1
SUSE-SU-2024:0900-2
SUSE-SU-2024:0910-1
SUSE-SU-2024:0926-1
SUSE-SU-2024:0977-1
SUSE-SU-2025:02334-1
SUSE-SU-2025_02334-1
USN-6725-1
USN-6725-2
USN-6765-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu