PT-2024-3476 · Linux+8 · Linux Kernel+8

Mingi Cho

·

Published

2024-03-07

·

Updated

2025-09-29

·

CVE-2024-26643

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.28
Description The issue is related to a race condition in the netfilter component of the Linux kernel, specifically in the nf tables module. This condition allows the rhashtable set gc to collect elements from anonymous sets with timeouts while they are being released from the commit path. The problem was originally reported by Mingi Cho in a different path in version 6.1.x with a pipapo set with low timeouts. To fix this, the dead flag is set for anonymous sets to skip async gc in this case. According to the plans, the abort path will be accelerated by releasing objects via a workqueue.
Recommendations To resolve the issue, upgrade the Linux kernel to version 6.6.28 or later. As a temporary workaround, consider disabling the netfilter nf tables module until a patch is available. Restrict access to the vulnerable nf tables module to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3306
ALSA-2024:3618
ALSA-2024:3627
ALSA-2025_16880
BDU:2024-03771
CESA-2024_3618
CESA-2024_3627
CVE-2024-26643
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_3306
INFSA-2024_3618
INFSA-2024_3627
MGASA-2024-0141
MGASA-2024-0142
OESA-2024-1682
OPENSUSE-SU-2024_2185-1
RHSA-2024:3306
RHSA-2024:3460
RHSA-2024:3461
RHSA-2024:3618
RHSA-2024:3627
RHSA-2024_3306
RHSA-2024_3618
RHSA-2024_3627
RLSA-2024:3618
RLSA-2024:3627
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:02588-1
SUSE-SU-2025:02849-1
SUSE-SU-2025:02851-1
SUSE-SU-2025:02852-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:2588-1
SUSE-SU-2025_02588-1
SUSE-SU-2025_02849-1
USN-6868-1
USN-6868-2
USN-6869-1
USN-6870-1
USN-6870-2
USN-6871-1
USN-6872-1
USN-6872-2
USN-6873-1
USN-6873-2
USN-6874-1
USN-6892-1
USN-6896-1
USN-6900-1
USN-6919-1
USN-6927-1

Affected Products

Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu