CVE-2024-26581
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval elements that are not yet active.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 2.22%• Percentile: 82%
Affected Systems
- debian•linux
< 5.10.216-1 | < 6.1.82-1 | < 6.7.7-1 | < 6.7.7-1
- ubuntu•linux
< 5.4.0-177.197 | < 5.15.0-105.115
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.4.0-1123.133 | < 5.15.0-1060.66
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1058.64~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1123.133~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
< 6.5.0-1018.18~22.04.1
- ubuntu•linux-aws-fips
< 5.4.0-1123.133+fips1 | all | < 5.15.0-1060.66+fips1
- ubuntu•linux-azure
all | < 5.4.0-1128.135 | < 5.15.0-1061.70
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1061.70~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1128.135~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
< 6.5.0-1019.20~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | < 5.15.0-1061.70.1 | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
< 5.4.0-1128.135+fips1 | all | < 5.15.0-1061.70+fips1
- ubuntu•linux-bluefield
all | < 5.4.0-1083.90 | < 5.15.0-1042.44
- ubuntu•linux-fips
< 5.4.0-1097.107 | < 5.15.0-105.115+fips1
- ubuntu•linux-gcp
all | < 5.4.0-1127.136 | < 5.15.0-1058.66
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1058.66~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1127.136~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.2
all
- ubuntu•linux-gcp-6.5
< 6.5.0-1018.18~22.04.1
- ubuntu•linux-gcp-fips
< 5.4.0-1127.136+fips1 | all | < 5.15.0-1058.66+fips1
- ubuntu•linux-gke
all | < 5.15.0-1057.62
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.15
all
- ubuntu•linux-gke-5.4
all
- ubuntu•linux-gkeop
< 5.4.0-1090.94 | < 5.15.0-1043.50
- ubuntu•linux-gkeop-5.15
< 5.15.0-1043.50~20.04.1
Showing first 50 affected entries in server-rendered view.
References (20)
- https://git.kernel.org/stable/c/c60d252949caf9aba537525195edae6bbabc35eb
- https://git.kernel.org/stable/c/10e9cb39313627f2eae4cd70c4b742074e998fd8
- https://git.kernel.org/stable/c/4cee42fcf54fec46b344681e7cc4f234bb22f85a
- https://git.kernel.org/stable/c/2bab493a5624444ec6e648ad0d55a362bcb4c003
- https://git.kernel.org/stable/c/1296c110c5a0b45a8fcf58e7d18bc5da61a565cb
- https://git.kernel.org/stable/c/b734f7a47aeb32a5ba298e4ccc16bb0c52b6dbf7
- https://git.kernel.org/stable/c/6eb14441f10602fa1cf691da9d685718b68b78a9
- https://git.kernel.org/stable/c/60c0c230c6f046da536d3df8b39a20b9a9fd6af0
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
- https://ubuntu.com/security/CVE-2024-26581
- https://git.kernel.org/linus/60c0c230c6f046da536d3df8b39a20b9a9fd6af0
- https://ubuntu.com/security/notices/USN-6688-1
- https://www.cve.org/CVERecord?id=CVE-2024-26581
- https://ubuntu.com/security/notices/USN-6741-1
- https://ubuntu.com/security/notices/USN-6742-1
- https://ubuntu.com/security/notices/USN-6743-1
- https://ubuntu.com/security/notices/USN-6743-2
- https://ubuntu.com/security/notices/USN-6742-2
- https://ubuntu.com/security/notices/USN-6743-3
- https://security-tracker.debian.org/tracker/CVE-2024-26581