PT-2024-3465 · Linux+6 · Linux Kernel+6

Syzbot

·

Published

2024-03-13

·

Updated

2025-09-29

·

CVE-2024-26815

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.8.0
Description The vulnerability is related to the taprio parse tc entry() function in the Linux kernel, which does not correctly check the TCA TAPRIO TC ENTRY INDEX attribute. This allows an attacker to feed arbitrary negative values, potentially leading to a shift-out-of-bounds error. The vulnerability was reported by syzbot and is related to the net/sched/sch taprio.c file.
Recommendations To resolve the issue, update the Linux kernel to version 6.8.0 or later. If updating is not possible, consider disabling the taprio module or restricting access to the vulnerable net/sched/sch taprio.c file as a temporary workaround. However, the most effective solution is to apply the proper patch for the TCA TAPRIO TC ENTRY INDEX check in the taprio parse tc entry() function.
Note: The provided information does not specify the exact patch or version that fixes the vulnerability, but it is implied that versions prior to 6.8.0 are affected.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-03753
CVE-2024-26815
DSA-5658-1
INFSA-2024_9315
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu