CVE-2024-26808

Source
https://cve.org/CVERecord?id=CVE-2024-26808
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26808.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26808
Downstream
Related
Published
2024-04-04T09:50:26.672Z
Modified
2026-06-18T03:56:10.327465559Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nftchainfilter: handle NETDEV_UNREGISTER for inet/ingress basechain

Remove netdevice from inet/ingress basechain in case NETDEV_UNREGISTER event is reported, otherwise a stale reference to netdevice remains in the hook list.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26808.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
60a3815da702fd9e4759945f26cce5c47d3967ad
Fixed
9489e214ea8f2a90345516016aa51f2db3a8cc2f
Fixed
70f17b48c86622217a58d5099d29242fc9adac58
Fixed
af149a46890e8285d1618bd68b8d159bdb87fdb3
Fixed
e5888acbf1a3d8d021990ce6c6061fd5b2bb21b4
Fixed
36a0a80f32209238469deb481967d777a3d539ee
Fixed
01acb2e8666a6529697141a6017edbf206921913

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26808.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.210
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.149
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.76
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.15
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26808.json"