Executive Summary

Informations
Name CVE-2024-26849 First vendor Publication 2024-04-17
Vendor Cve Last vendor Modification 2025-02-03

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

netlink: add nla be16/32 types to minlen array

BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline] BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline] BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631
nla_validate_range_unsigned lib/nlattr.c:222 [inline]
nla_validate_int_range lib/nlattr.c:336 [inline]
validate_nla lib/nlattr.c:575 [inline] ...

The message in question matches this policy:

[NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255),

but because NLA_BE32 size in minlen array is 0, the validation code will read past the malformed (too small) attribute.

Note: Other attributes, e.g. BITFIELD32, SINT, UINT.. are also missing: those likely should be added too.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26849

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3656

Sources (Detail)

https://git.kernel.org/stable/c/0ac219c4c3ab253f3981f346903458d20bacab32
https://git.kernel.org/stable/c/7a9d14c63b35f89563c5ecbadf918ad64979712d
https://git.kernel.org/stable/c/9a0d18853c280f6a0ee99f91619f2442a17a323a
https://git.kernel.org/stable/c/a2ab028151841cd833cb53eb99427e0cc990112d
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2025-07-15 02:32:13
  • Multiple Updates
2025-07-14 12:31:29
  • Multiple Updates
2025-06-26 02:29:47
  • Multiple Updates
2025-06-25 12:29:56
  • Multiple Updates
2025-06-24 02:34:15
  • Multiple Updates
2025-05-27 02:36:12
  • Multiple Updates
2025-03-29 03:35:27
  • Multiple Updates
2025-03-28 13:41:30
  • Multiple Updates
2025-03-28 03:14:30
  • Multiple Updates
2025-03-19 03:10:05
  • Multiple Updates
2025-03-18 03:22:46
  • Multiple Updates
2025-03-14 03:10:21
  • Multiple Updates
2025-02-22 03:20:13
  • Multiple Updates
2025-02-03 21:21:58
  • Multiple Updates
2024-11-25 09:26:05
  • Multiple Updates
2024-04-17 17:28:37
  • First insertion