CVE-2024-26739 (GCVE-0-2024-26739)
Vulnerability from cvelistv5
Published
2024-04-03 17:00
Modified
2026-08-05 11:26
Summary
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcode to SHOT. If we have called tcf_mirred_forward(), however, the skb is out of our hands and returning SHOT will lead to UaF. Move the retval override to the error path which actually need it.
Impacted products
Vendor Product Version
Linux Linux Version: e5cf1baf92cb785b90390db1c624948e70c8b8bd
Version: e5cf1baf92cb785b90390db1c624948e70c8b8bd
Version: e5cf1baf92cb785b90390db1c624948e70c8b8bd
Version: e5cf1baf92cb785b90390db1c624948e70c8b8bd
Version: e5cf1baf92cb785b90390db1c624948e70c8b8bd
Version: e5cf1baf92cb785b90390db1c624948e70c8b8bd
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T19:29:31.734Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26739",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:51:53.930424Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:18.399Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/sched/act_mirred.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd",
              "status": "affected",
              "version": "e5cf1baf92cb785b90390db1c624948e70c8b8bd",
              "versionType": "git"
            },
            {
              "lessThan": "9d3ef89b6a5e9f2e940de2cef3d543be0be8dec5",
              "status": "affected",
              "version": "e5cf1baf92cb785b90390db1c624948e70c8b8bd",
              "versionType": "git"
            },
            {
              "lessThan": "e873e8f7d03a2ee5b77fb1a305c782fed98e2754",
              "status": "affected",
              "version": "e5cf1baf92cb785b90390db1c624948e70c8b8bd",
              "versionType": "git"
            },
            {
              "lessThan": "28cdbbd38a4413b8eff53399b3f872fd4e80db9d",
              "status": "affected",
              "version": "e5cf1baf92cb785b90390db1c624948e70c8b8bd",
              "versionType": "git"
            },
            {
              "lessThan": "f4e294bbdca8ac8757db436fc82214f3882fc7e7",
              "status": "affected",
              "version": "e5cf1baf92cb785b90390db1c624948e70c8b8bd",
              "versionType": "git"
            },
            {
              "lessThan": "166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210",
              "status": "affected",
              "version": "e5cf1baf92cb785b90390db1c624948e70c8b8bd",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/sched/act_mirred.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "lessThan": "4.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.238",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.182",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.136",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.238",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.182",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.136",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.19",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.7",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_mirred: don\u0027t override retval if we already lost the skb\n\nIf we\u0027re redirecting the skb, and haven\u0027t called tcf_mirred_forward(),\nyet, we need to tell the core to drop the skb by setting the retcode\nto SHOT. If we have called tcf_mirred_forward(), however, the skb\nis out of our hands and returning SHOT will lead to UaF.\n\nMove the retval override to the error path which actually need it."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable configuration (ingress qdisc + filter with an act_mirred redirect) must be installed locally via rtnetlink, and the attacker drives the trigger by injecting frames locally into that device. Per kernel scoring convention, tc/qdisc netlink-configured paths are Local.\nAC:L - There is no race or memory-layout precondition; the attacker fully controls both the mirred configuration and the drop condition (unhandled ethertype, or a drop filter/saturated qdisc on the target device), so every injected packet deterministically produces the double free.\nPR:L - Configuring the mirred action requires only CAP_NET_ADMIN within a network namespace, which any unprivileged user obtains via `unshare -Urn`; CAP_NET_RAW in that same user namespace supplies the AF_PACKET frame injection.\nUI:N - The attacker sets up the qdisc/filter and sends the packets entirely on their own; no action by any other user or administrator is needed.\nS:U - The corruption is confined to the kernel\u0027s own heap and privilege domain; no VM, IOMMU, or other security-authority boundary is crossed.\nC:H - The skb and its data buffer are freed twice, so the same slab object is handed to two owners; this use-after-free lets an attacker read the contents of a kernel object aliased onto the reclaimed skb, giving arbitrary kernel memory disclosure.\nI:H - The same double-free/UAF primitive permits heap spraying of the reclaimed skb with attacker-controlled data, yielding a write primitive over adjacent kernel structures and a path to control-flow hijack and privilege escalation.\nA:H - Even without further exploitation, freeing an already-freed skb corrupts the slab freelist and reliably triggers a kernel oops/panic (or BUG on a debug kernel), and it can be repeated at packet rate."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:26:57.172Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd"
        },
        {
          "url": "https://git.kernel.org/stable/c/9d3ef89b6a5e9f2e940de2cef3d543be0be8dec5"
        },
        {
          "url": "https://git.kernel.org/stable/c/e873e8f7d03a2ee5b77fb1a305c782fed98e2754"
        },
        {
          "url": "https://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d"
        },
        {
          "url": "https://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7"
        },
        {
          "url": "https://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210"
        }
      ],
      "title": "net/sched: act_mirred: don\u0027t override retval if we already lost the skb",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26739",
    "datePublished": "2024-04-03T17:00:24.879Z",
    "dateReserved": "2024-02-19T14:20:24.166Z",
    "dateUpdated": "2026-08-05T11:26:57.172Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T19:29:31.734Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26739\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:51:53.930424Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:16.047Z\"}}], \"cna\": {\"title\": \"net/sched: act_mirred: don\u0027t override retval if we already lost the skb\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerable configuration (ingress qdisc + filter with an act_mirred redirect) must be installed locally via rtnetlink, and the attacker drives the trigger by injecting frames locally into that device. Per kernel scoring convention, tc/qdisc netlink-configured paths are Local.\\nAC:L - There is no race or memory-layout precondition; the attacker fully controls both the mirred configuration and the drop condition (unhandled ethertype, or a drop filter/saturated qdisc on the target device), so every injected packet deterministically produces the double free.\\nPR:L - Configuring the mirred action requires only CAP_NET_ADMIN within a network namespace, which any unprivileged user obtains via `unshare -Urn`; CAP_NET_RAW in that same user namespace supplies the AF_PACKET frame injection.\\nUI:N - The attacker sets up the qdisc/filter and sends the packets entirely on their own; no action by any other user or administrator is needed.\\nS:U - The corruption is confined to the kernel\u0027s own heap and privilege domain; no VM, IOMMU, or other security-authority boundary is crossed.\\nC:H - The skb and its data buffer are freed twice, so the same slab object is handed to two owners; this use-after-free lets an attacker read the contents of a kernel object aliased onto the reclaimed skb, giving arbitrary kernel memory disclosure.\\nI:H - The same double-free/UAF primitive permits heap spraying of the reclaimed skb with attacker-controlled data, yielding a write primitive over adjacent kernel structures and a path to control-flow hijack and privilege escalation.\\nA:H - Even without further exploitation, freeing an already-freed skb corrupts the slab freelist and reliably triggers a kernel oops/panic (or BUG on a debug kernel), and it can be repeated at packet rate.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"e5cf1baf92cb785b90390db1c624948e70c8b8bd\", \"lessThan\": \"0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e5cf1baf92cb785b90390db1c624948e70c8b8bd\", \"lessThan\": \"9d3ef89b6a5e9f2e940de2cef3d543be0be8dec5\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e5cf1baf92cb785b90390db1c624948e70c8b8bd\", \"lessThan\": \"e873e8f7d03a2ee5b77fb1a305c782fed98e2754\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e5cf1baf92cb785b90390db1c624948e70c8b8bd\", \"lessThan\": \"28cdbbd38a4413b8eff53399b3f872fd4e80db9d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e5cf1baf92cb785b90390db1c624948e70c8b8bd\", \"lessThan\": \"f4e294bbdca8ac8757db436fc82214f3882fc7e7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e5cf1baf92cb785b90390db1c624948e70c8b8bd\", \"lessThan\": \"166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210\", \"versionType\": \"git\"}], \"programFiles\": [\"net/sched/act_mirred.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.19\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.19\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.238\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.182\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.136\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.19\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.7\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/sched/act_mirred.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd\"}, {\"url\": \"https://git.kernel.org/stable/c/9d3ef89b6a5e9f2e940de2cef3d543be0be8dec5\"}, {\"url\": \"https://git.kernel.org/stable/c/e873e8f7d03a2ee5b77fb1a305c782fed98e2754\"}, {\"url\": \"https://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d\"}, {\"url\": \"https://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7\"}, {\"url\": \"https://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet/sched: act_mirred: don\u0027t override retval if we already lost the skb\\n\\nIf we\u0027re redirecting the skb, and haven\u0027t called tcf_mirred_forward(),\\nyet, we need to tell the core to drop the skb by setting the retcode\\nto SHOT. If we have called tcf_mirred_forward(), however, the skb\\nis out of our hands and returning SHOT will lead to UaF.\\n\\nMove the retval override to the error path which actually need it.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.238\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.182\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.136\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.19\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.7\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"4.19\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:26:57.172Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26739\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:26:57.172Z\", \"dateReserved\": \"2024-02-19T14:20:24.166Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-03T17:00:24.879Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…