CVE-2024-26809

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26809
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26809.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26809
Downstream
Related
Published
2024-04-04T09:51:51.245Z
Modified
2025-11-28T02:35:31.801552Z
Summary
netfilter: nft_set_pipapo: release elements in clone only from destroy path
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nftsetpipapo: release elements in clone only from destroy path

Clone already always provides a current view of the lookup table, use it to destroy the set, otherwise it is possible to destroy elements twice.

This fix requires:

212ed75dc5fb ("netfilter: nf_tables: integrate pipapo into commit protocol")

which came after:

9827a0e6e23b ("netfilter: nftsetpipapo: release elements in clone from abort path").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26809.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4a6430b99f67842617c7208ca55a411e903ba03a
Fixed
b36b83297ff4910dfc8705402c8abffd4bbf8144
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5ccecafc728b0df48263d5ac198220bcd79830bc
Fixed
362508506bf545e9ce18c72a2c48dcbfb891ab9c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e
Fixed
5ad233dc731ab64cdc47b84a5c1f78fff6c024af
Fixed
ff90050771412b91e928093ccd8736ae680063c2
Fixed
821e28d5b506e6a73ccc367ff792bd894050d48b
Fixed
9384b4d85c46ce839f51af01374062ce6318b2f2
Fixed
b0e256f3dd2ba6532f37c5c22e07cb07a36031ee
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
d2b18d110685ce46ca1633b8ec586c685e243a51

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.214
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.153
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.83
Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.6.23
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.7.11
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.2