PT-2024-3383 · Linux+9 · Linux Kernel+9

Zhangpeng

·

Published

2024-01-29

·

Updated

2025-09-29

·

CVE-2024-26640

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the Linux kernel's TCP rx zerocopy functionality, which is intended to map pages initially allocated from NIC drivers, not pages owned by a file system. A patch has been added to include additional checks in the can map frag() function to prevent potential issues, such as panics reported by ZhangPeng. The vulnerability could be exploited by an attacker to cause a denial of service. Technical details about exploitation include the use of sendfile() to map pages owned by an ext4 file to TCP rx zerocopy.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5101
ALSA-2024:5102
ALSA-2024:8617
ALSA-2025_16880
BDU:2024-03655
CESA-2024_5101
CESA-2024_5102
CVE-2024-26640
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_5101
INFSA-2024_5102
INFSA-2024_8617
OESA-2024-1566
OESA-2024-1567
OESA-2024-1568
OESA-2024-1647
OESA-2024-1648
OESA-2024-1649
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
RHSA-2024:5065
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024:5255
RHSA-2024:8617
RHSA-2024:9497
RHSA-2024:9498
RHSA-2024_5101
RHSA-2024_5102
RHSA-2024_8617
RLSA-2024:5101
RLSA-2024:5102
RLSA-2024:8617
RXSA-2024:5101
SUSE-SU-2024:3551-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3592-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-6765-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6795-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6828-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7119-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu