CVE-2024-26855

Source
https://cve.org/CVERecord?id=CVE-2024-26855
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26855.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26855
Downstream
Related
Published
2024-04-17T10:17:17.858Z
Modified
2026-05-28T03:52:58.506215203Z
Summary
net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ice: Fix potential NULL pointer dereference in icebridgesetlink()

The function icebridgesetlink() may encounter a NULL pointer dereference if nlmsgfindattr() returns NULL and brspec is dereferenced subsequently in nlaforeachnested(). To address this issue, add a check to ensure that br_spec is not NULL before proceeding with the nested attribute iteration.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26855.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b1edc14a3fbfe0154a2aecb8bb9775c3012cb6e2
Fixed
d9fefc51133107e59d192d773be86c1150cfeebb
Fixed
37fe99016b12d32100ce670216816dba6c48b309
Fixed
8d95465d9a424200485792858c5b3be54658ce19
Fixed
afdd29726a6de4ba27cd15590661424c888dc596
Fixed
1a770927dc1d642b22417c3e668c871689fc58b3
Fixed
0e296067ae0d74a10b4933601f9aa9f0ec8f157f
Fixed
06e456a05d669ca30b224b8ed962421770c1496c

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26855.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.272
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.213
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.152
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.82
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.22
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26855.json"