PT-2024-3382 · Linux+4 · Linux Kernel+4
Марк Коренберг
·
Published
2024-01-22
·
Updated
2025-06-12
·
CVE-2024-26634
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to the removal of a namespace with conflicting altnames in the Linux kernel. When a net namespace is removed, it may cause a kernel bug, potentially leading to the overwriting of the main interface name. The problem arises when physical interfaces are moved outside of init net and get "refunded" to init net when the namespace disappears. Recent fixes have addressed ensuring that altnames get moved with the main interface, which has surfaced this problem. The vulnerability is associated with the use of memory after it has been freed, which could impact the confidentiality, integrity, and availability of protected information.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu