PT-2024-3382 · Linux+4 · Linux Kernel+4

Марк Коренберг

·

Published

2024-01-22

·

Updated

2025-06-12

·

CVE-2024-26634

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the removal of a namespace with conflicting altnames in the Linux kernel. When a net namespace is removed, it may cause a kernel bug, potentially leading to the overwriting of the main interface name. The problem arises when physical interfaces are moved outside of init net and get "refunded" to init net when the namespace disappears. Recent fixes have addressed ensuring that altnames get moved with the main interface, which has surfaced this problem. The vulnerability is associated with the use of memory after it has been freed, which could impact the confidentiality, integrity, and availability of protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03654
CVE-2024-26634
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
SUSE-SU-2025_1241-1
USN-6765-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4

Affected Products

Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu