CVE-2024-26581

HIGH

Linux Kernel - Use-After-Free in nft_set_rbtree Lazy GC

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-26581. PoCs published by madfxr.

AI-analyzed exploit summary This repository contains two bash scripts that check for the presence of CVE-2024-26581, a vulnerability affecting certain Linux kernel versions. The scripts verify kernel versions and nftables configurations to determine if the system is affected.

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval elements that are not yet active.

Exploits (1)

nomisec SCANNER 2 stars
by madfxr · poc
https://github.com/madfxr/CVE-2024-26581-Checker

This repository contains two bash scripts that check for the presence of CVE-2024-26581, a vulnerability affecting certain Linux kernel versions. The scripts verify kernel versions and nftables configurations to determine if the system is affected.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Linux kernel (specific versions)
No auth needed
Prerequisites: Access to the target system's kernel version and nftables configuration
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (31)
debian/debian_linux 10.0
linux/Kernel < 5.4.269linux
linux/Kernel 5.11.0 - 5.15.149linux
linux/Kernel 5.16.0 - 6.1.78linux
linux/Kernel 5.5.0 - 5.10.210linux
linux/Kernel 6.2.0 - 6.6.17linux
linux/Kernel 6.5.0 - 6.7.5linux
Linux/Linux < 6.5
Linux/Linux 5.10.190 - 5.10.210
Linux/Linux 5.10.210 - 5.10.*
... and 21 more
Published Feb 20, 2024
Tracked Since Feb 18, 2026