CVE-2024-26581: netfilter: nft_set_rbtree: skip end interval element from gc
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftsetrbtree: skip end interval element from gc
rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval elements that are not yet active.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.78
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26581?
CVE-2024-26581 has been classified with a medium severity level due to its potential impact on the Linux kernel's netfilter functionality.
How do I fix CVE-2024-26581?
To fix CVE-2024-26581, upgrade the Linux kernel to version 6.1.78 or later for affected Red Hat distributions, or apply available patches for Debian-based systems.
Which versions of the Linux kernel are affected by CVE-2024-26581?
CVE-2024-26581 affects Linux kernel versions between 5.4.269 and 6.1.78, as well as several subranges within those versions.
Is there a workaround for CVE-2024-26581?
No specific workarounds have been documented for CVE-2024-26581, so upgrading is the recommended course of action.
Can CVE-2024-26581 be exploited remotely?
CVE-2024-26581 could potentially be exploited remotely depending on the specific usage of affected systems within a network.