PT-2024-7731 · Linux+5 · Linux Kernel+5
Thomas Gleixner
·
Published
2024-02-19
·
Updated
2025-09-29
·
CVE-2024-26803
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The vulnerability is related to the Linux kernel's virtual Ethernet (veth) component. When XDP (eXpress Data Path) is enabled, veth sets the NETIF F GRO flag automatically because both features use the same NAPI machinery. However, the logic to clear this flag is skipped when the device is brought down, which can lead to a stray GRO flag being set when XDP is disabled and then the device is brought up. This can cause the system to crash or hang when features are synchronized, either by the user via ethtool or by a peer changing its configuration.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Ubuntu