PT-2024-7857 · Linux+5 · Linux Kernel+5

Martin Zaharinov

·

Published

2024-03-14

·

Updated

2025-03-27

·

CVE-2024-27026

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 6.5.1
Description The vulnerability is related to the vmxnet3 component of the Linux kernel, specifically with errors in resource management in the vmxnet3 process xdp() function. This issue can lead to a denial of service. The problem arises from a missing reserved tailroom, which is fixed by using rbi->len instead of rcd->len for non-dataring packets. Technical details include the involvement of xdp do redirect(), vmxnet3 run xdp(), and vmxnet3 process xdp() functions, indicating a complex interaction within the kernel's networking components.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the missing reserved tailroom in the vmxnet3 component. Specifically, ensure that the kernel version is later than 6.5.1, as this version and earlier are affected.
Note: The provided information does not specify the exact version where the fix is applied, so it's recommended to update to the latest available kernel version to ensure the inclusion of the necessary patches.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09359
CVE-2024-27026
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3986-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu