CVE-2024-26677

MEDIUM

Linux Kernel < 6.6.17 - NULL Pointer Dereference

Title source: rule

Description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix delayed ACKs to not set the reference serial number Fix the construction of delayed ACKs to not set the reference serial number as they can't be used as an RTT reference.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-476
Status published

Affected Products (6)

linux/linux_kernel < 6.6.17
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/Kernel < 6.6.17linux
linux/Kernel < 6.7.5linux

Timeline

Published Apr 02, 2024
Tracked Since Feb 18, 2026