CVE-2024-26634

MEDIUM

Linux Kernel - Denial of Service via Net Namespace Removal with Conflicting AltNames

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: fix removing a namespace with conflicting altnames Mark reports a BUG() when a net namespace is removed. kernel BUG at net/core/dev.c:11520! Physical interfaces moved outside of init_net get "refunded" to init_net when that namespace disappears. The main interface name may get overwritten in the process if it would have conflicted. We need to also discard all conflicting altnames. Recent fixes addressed ensuring that altnames get moved with the main interface, which surfaced this problem.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (18)
linux/Kernel < 6.1.76linux
linux/Kernel 6.2.0 - 6.6.15linux
linux/Kernel 6.6.0 - 6.7.3linux
Linux/Linux < 6.6
Linux/Linux 6.1.60 - 6.1.76
Linux/Linux 6.1.76 - 6.1.*
Linux/Linux 6.5.9 - 6.6
Linux/Linux 6.6
Linux/Linux 6.6.15 - 6.6.*
Linux/Linux 6.7.3 - 6.7.*
... and 8 more
Published Mar 18, 2024
Tracked Since Feb 18, 2026