Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout from userspace, reject this. Exception to this rule is NFT_SET_EVAL to ensure legacy meters still work.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.1, < 4.19.312 |
| Debian | Debian Linux | 10.0 |
References
- https://git.kernel.org/stable/c/16603605b667b70da974bea8216c93e7db043bf1Patch
- https://git.kernel.org/stable/c/72c1efe3f247a581667b7d368fff3bd9a03cd57aPatch
- https://git.kernel.org/stable/c/7cdc1be24cc1bcd56a3e89ac4aef20e31ad09199Patch
- https://git.kernel.org/stable/c/8e07c16695583a66e81f67ce4c46e94dece47ba7Patch
- https://git.kernel.org/stable/c/c0c2176d1814b92ea4c8e7eb7c9cd94cd99c1b12Patch
- https://git.kernel.org/stable/c/e4988d8415bd0294d6f9f4a1e7095f8b50a97ca9Patch
- https://git.kernel.org/stable/c/e9a0d3f376eb356d54ffce36e7cc37514cbfbd6fPatch
- https://git.kernel.org/stable/c/fe40ffbca19dc70d7c6b1e3c77b9ccb404c57351Patch
- https://git.kernel.org/stable/c/16603605b667b70da974bea8216c93e7db043bf1Patch
- https://git.kernel.org/stable/c/72c1efe3f247a581667b7d368fff3bd9a03cd57aPatch
- https://git.kernel.org/stable/c/7cdc1be24cc1bcd56a3e89ac4aef20e31ad09199Patch
- https://git.kernel.org/stable/c/8e07c16695583a66e81f67ce4c46e94dece47ba7Patch
- https://git.kernel.org/stable/c/c0c2176d1814b92ea4c8e7eb7c9cd94cd99c1b12Patch
- https://git.kernel.org/stable/c/e4988d8415bd0294d6f9f4a1e7095f8b50a97ca9Patch
- https://git.kernel.org/stable/c/e9a0d3f376eb356d54ffce36e7cc37514cbfbd6fPatch
FAQ
What is CVE-2024-26642?
CVE-2024-26642 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout from userspace, reject t...
How severe is CVE-2024-26642?
CVE-2024-26642 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26642?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.