PT-2024-6076 · Linux+4 · Linux Kernel+4

Horatiu Vultur

·

Published

2024-02-09

·

Updated

2024-10-22

·

CVE-2024-26723

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a crash when adding a lan966x interface under a lag interface in the Linux kernel. This can be reproduced by running specific commands, such as "ip link add name bond0 type bond miimon 100 mode balance-xor" and "ip link set dev eth0 master bond0". The reason for the crash is that the lan966x can have ports that are NULL pointers as they are not probed, causing the system to crash when iterating over these ports. The fix involves checking for NULL pointers before accessing something from the ports.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06901
CVE-2024-26723
DSA-5658-1
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu