[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-26921":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":18,"aliases":19,"duplicate_of":9,"upstream":20,"downstream":21,"duplicates":110,"related":111,"reserved_at":9,"published_at":130,"modified_at":131,"state":132,"summary":133,"references_raw":142,"kevs":177,"epss":178,"epss_history":181,"metrics":450,"affected":456},"CVE-2024-26921","In the Linux kernel, the following vulnerability has been resolved:\n\ninet: inet_defrag: prevent sk release while still in use\n\nip_local_out() and other functions can pass skb->sk as function argument.\n\nIf the skb is a fragment and reassembly happens before such function call\nreturns, the sk must not be released.\n\nThis affects skb fragments reassembled via netfilter or similar\nmodules, e.g. openvswitch or ct_act.c, when run as part of tx pipeline.\n\nEric Dumazet made an initial analysis of this bug.  Quoting Eric:\n  Calling ip_defrag() in output path is also implying skb_orphan(),\n  which is buggy because output path relies on sk not disappearing.\n\n  A relevant old patch about the issue was :\n  8282f27449bf (\"inet: frag: Always orphan skbs inside ip_defrag()\")\n\n  [..]\n\n  net/ipv4/ip_output.c depends on skb->sk being set, and probably to an\n  inet socket, not an arbitrary one.\n\n  If we orphan the packet in ipvlan, then downstream things like FQ\n  packet scheduler will not work properly.\n\n  We need to change ip_defrag() to only use skb_orphan() when really\n  needed, ie whenever frag_list is going to be used.\n\nEric suggested to stash sk in fragment queue and made an initial patch.\nHowever there is a problem with this:\n\nIf skb is refragmented again right after, ip_do_fragment() will copy\nhead->sk to the new fragments, and sets up destructor to sock_wfree.\nIOW, we have no choice but to fix up sk_wmem accouting to reflect the\nfully reassembled skb, else wmem will underflow.\n\nThis change moves the orphan down into the core, to last possible moment.\nAs ip_defrag_offset is aliased with sk_buff->sk member, we must move the\noffset into the FRAG_CB, else skb->sk gets clobbered.\n\nThis allows to delay the orphaning long enough to learn if the skb has\nto be queued or if the skb is completing the reasm queue.\n\nIn the former case, things work as before, skb is orphaned.  This is\nsafe because skb gets queued/stolen and won't continue past reasm engine.\n\nIn the latter case, we will steal the skb->sk reference, reattach it to\nthe head skb, and fix up wmem accouting when inet_frag inflates truesize.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":9,"likelihood_of_exploit":9,"capec":17},"NVD-CWE-NOINFO","Insufficient Information","NVD uses this CWE ID when there is insufficient information to assign a specific CWE.","placeholder","NVD-Reserved",[],[],[],[],[22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88,90,92,94,96,98,100,102,104,106,108],{"_key":23},"SUSE-SU-2024:2185-1",{"_key":25},"SUSE-SU-2024:2203-1",{"_key":27},"SUSE-SU-2024:1979-1",{"_key":29},"SUSE-SU-2024:1983-1",{"_key":31},"SUSE-SU-2024:2010-1",{"_key":33},"SUSE-SU-2024:2184-1",{"_key":35},"SUSE-SU-2024:2365-1",{"_key":37},"SUSE-SU-2024:2008-1",{"_key":39},"SUSE-SU-2024:2011-1",{"_key":41},"SUSE-SU-2024:2019-1",{"_key":43},"SUSE-SU-2024:2135-1",{"_key":45},"SUSE-SU-2024:2189-1",{"_key":47},"SUSE-SU-2024:2190-1",{"_key":49},"SUSE-SU-2024:2973-1",{"_key":51},"DLA-4075-1",{"_key":53},"SUSE-SU-2025:20008-1",{"_key":55},"SUSE-SU-2025:20028-1",{"_key":57},"MGASA-2024-0141",{"_key":59},"MGASA-2024-0142",{"_key":61},"DEBIAN-CVE-2024-26921",{"_key":63},"RHSA-2024:5101",{"_key":65},"RHSA-2024:5102",{"_key":67},"RHSA-2025:8796",{"_key":69},"RHSA-2024:9315",{"_key":71},"LSN-0107-1",{"_key":73},"LSN-0108-1",{"_key":75},"LSN-0109-1",{"_key":77},"UBUNTU-CVE-2024-26921",{"_key":79},"USN-6974-1",{"_key":81},"USN-6974-2",{"_key":83},"USN-7429-1",{"_key":85},"USN-7429-2",{"_key":87},"USN-6893-1",{"_key":89},"USN-6893-2",{"_key":91},"USN-6893-3",{"_key":93},"USN-6918-1",{"_key":95},"USN-6973-1",{"_key":97},"USN-6973-2",{"_key":99},"USN-6973-3",{"_key":101},"USN-6973-4",{"_key":103},"USN-7006-1",{"_key":105},"USN-7019-1",{"_key":107},"USN-7185-1",{"_key":109},"USN-7185-2",[],[112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129],{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":53},{"_key":55},{"_key":57},{"_key":59},"2024-04-18T09:47:58.632Z","2026-05-11T20:06:57.402Z","Modified",{"cisa_kev":134,"cisa_ransomware":134,"cisa_vendor":9,"epss_severity":135,"epss_score":136,"severity":137,"severity_score":138,"severity_version":139,"severity_source":140,"severity_vector":141,"severity_status":132},false,"low",0.00078,"medium",5.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[143,149,153,157,161,165,169,173],{"url":144,"sources":145,"tags":147},"https://git.kernel.org/stable/c/1b6de5e6575b56502665c65cf93b0ae6aa0f51ab",[146,140],"cve.org",[148],"Patch",{"url":150,"sources":151,"tags":152},"https://git.kernel.org/stable/c/9705f447bf9a6cd088300ad2c407b5e1c6591091",[146,140],[148],{"url":154,"sources":155,"tags":156},"https://git.kernel.org/stable/c/4318608dc28ef184158b4045896740716bea23f0",[146,140],[148],{"url":158,"sources":159,"tags":160},"https://git.kernel.org/stable/c/7d0567842b78390dd9b60f00f1d8f838d540e325",[146,140],[148],{"url":162,"sources":163,"tags":164},"https://git.kernel.org/stable/c/f4877225313d474659ee53150ccc3d553a978727",[146,140],[148],{"url":166,"sources":167,"tags":168},"https://git.kernel.org/stable/c/e09cbe017311508c21e0739e97198a8388b98981",[146,140],[148],{"url":170,"sources":171,"tags":172},"https://git.kernel.org/stable/c/18685451fc4e546fc0e718580d32df3c0e5c8272",[146,140],[148],{"url":174,"sources":175,"tags":176},"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html",[146,140],[],[],{"date":179,"score":136,"percentile":180},"2026-06-03",0.23278,[182,186,189,192,195,198,200,203,206,209,212,215,218,221,224,228,231,234,238,241,244,247,250,253,256,259,262,265,268,271,274,277,280,283,285,288,291,294,297,300,303,306,309,312,315,318,321,324,327,330,333,336,339,342,345,348,351,354,356,359,362,365,368,371,374,377,380,383,386,389,392,395,398,400,402,405,408,411,414,417,420,423,426,429,432,435,438,441,444,447],{"date":183,"score":184,"percentile":185},"2025-11-04",0.00057,0.17847,{"date":187,"score":184,"percentile":188},"2025-11-05",0.17864,{"date":190,"score":184,"percentile":191},"2025-11-06",0.17833,{"date":193,"score":184,"percentile":194},"2025-11-07",0.17858,{"date":196,"score":184,"percentile":197},"2025-11-08",0.17859,{"date":199,"score":184,"percentile":191},"2025-11-09",{"date":201,"score":184,"percentile":202},"2025-11-10",0.17792,{"date":204,"score":184,"percentile":205},"2025-11-11",0.17807,{"date":207,"score":184,"percentile":208},"2025-11-12",0.17844,{"date":210,"score":184,"percentile":211},"2025-11-13",0.17873,{"date":213,"score":184,"percentile":214},"2025-11-14",0.17871,{"date":216,"score":184,"percentile":217},"2025-11-15",0.17838,{"date":219,"score":184,"percentile":220},"2025-11-16",0.17803,{"date":222,"score":184,"percentile":223},"2025-11-17",0.17768,{"date":225,"score":226,"percentile":227},"2025-11-18",0.00382,0.56796,{"date":229,"score":226,"percentile":230},"2025-11-19",0.56812,{"date":232,"score":226,"percentile":233},"2025-11-20",0.56802,{"date":235,"score":236,"percentile":237},"2025-11-21",0.00059,0.18345,{"date":239,"score":236,"percentile":240},"2025-11-22",0.18352,{"date":242,"score":184,"percentile":243},"2025-11-23",0.17766,{"date":245,"score":184,"percentile":246},"2025-11-24",0.17731,{"date":248,"score":184,"percentile":249},"2025-11-25",0.17721,{"date":251,"score":184,"percentile":252},"2025-11-26",0.17716,{"date":254,"score":184,"percentile":255},"2025-11-27",0.17719,{"date":257,"score":184,"percentile":258},"2025-11-28",0.17709,{"date":260,"score":184,"percentile":261},"2025-11-29",0.17695,{"date":263,"score":184,"percentile":264},"2025-11-30",0.17698,{"date":266,"score":184,"percentile":267},"2025-12-01",0.1774,{"date":269,"score":184,"percentile":270},"2025-12-02",0.1775,{"date":272,"score":184,"percentile":273},"2025-12-03",0.17763,{"date":275,"score":184,"percentile":276},"2025-12-04",0.17724,{"date":278,"score":184,"percentile":279},"2025-12-05",0.17777,{"date":281,"score":184,"percentile":282},"2025-12-06",0.17782,{"date":284,"score":184,"percentile":273},"2025-12-07",{"date":286,"score":184,"percentile":287},"2025-12-08",0.17775,{"date":289,"score":184,"percentile":290},"2025-12-09",0.17842,{"date":292,"score":184,"percentile":293},"2025-12-10",0.17904,{"date":295,"score":184,"percentile":296},"2025-12-11",0.17951,{"date":298,"score":184,"percentile":299},"2025-12-12",0.17994,{"date":301,"score":184,"percentile":302},"2025-12-13",0.18005,{"date":304,"score":184,"percentile":305},"2025-12-14",0.17953,{"date":307,"score":184,"percentile":308},"2025-12-15",0.17932,{"date":310,"score":184,"percentile":311},"2025-12-16",0.17966,{"date":313,"score":184,"percentile":314},"2025-12-17",0.18054,{"date":316,"score":184,"percentile":317},"2025-12-18",0.18144,{"date":319,"score":184,"percentile":320},"2025-12-19",0.18156,{"date":322,"score":184,"percentile":323},"2025-12-20",0.18139,{"date":325,"score":184,"percentile":326},"2025-12-21",0.18081,{"date":328,"score":184,"percentile":329},"2025-12-22",0.18035,{"date":331,"score":184,"percentile":332},"2025-12-23",0.18041,{"date":334,"score":184,"percentile":335},"2025-12-24",0.18073,{"date":337,"score":184,"percentile":338},"2025-12-25",0.18151,{"date":340,"score":184,"percentile":341},"2025-12-26",0.18136,{"date":343,"score":184,"percentile":344},"2025-12-27",0.18127,{"date":346,"score":184,"percentile":347},"2025-12-28",0.18094,{"date":349,"score":184,"percentile":350},"2025-12-29",0.18059,{"date":352,"score":184,"percentile":353},"2025-12-30",0.18072,{"date":355,"score":184,"percentile":323},"2025-12-31",{"date":357,"score":184,"percentile":358},"2026-01-01",0.18241,{"date":360,"score":184,"percentile":361},"2026-01-02",0.18228,{"date":363,"score":184,"percentile":364},"2026-01-03",0.18206,{"date":366,"score":184,"percentile":367},"2026-01-04",0.181,{"date":369,"score":184,"percentile":370},"2026-01-05",0.18067,{"date":372,"score":184,"percentile":373},"2026-01-06",0.18083,{"date":375,"score":184,"percentile":376},"2026-01-07",0.18116,{"date":378,"score":184,"percentile":379},"2026-01-08",0.18178,{"date":381,"score":184,"percentile":382},"2026-01-09",0.1818,{"date":384,"score":184,"percentile":385},"2026-01-10",0.18198,{"date":387,"score":184,"percentile":388},"2026-01-11",0.1816,{"date":390,"score":184,"percentile":391},"2026-01-12",0.18119,{"date":393,"score":184,"percentile":394},"2026-01-13",0.18096,{"date":396,"score":184,"percentile":397},"2026-01-14",0.18145,{"date":399,"score":184,"percentile":397},"2026-01-15",{"date":401,"score":184,"percentile":382},"2026-01-16",{"date":403,"score":184,"percentile":404},"2026-01-17",0.18188,{"date":406,"score":184,"percentile":407},"2026-01-18",0.18124,{"date":409,"score":184,"percentile":410},"2026-01-19",0.18058,{"date":412,"score":184,"percentile":413},"2026-01-20",0.18039,{"date":415,"score":184,"percentile":416},"2026-01-21",0.18012,{"date":418,"score":184,"percentile":419},"2026-01-22",0.1794,{"date":421,"score":184,"percentile":422},"2026-01-23",0.18037,{"date":424,"score":184,"percentile":425},"2026-01-24",0.18066,{"date":427,"score":184,"percentile":428},"2026-01-25",0.17993,{"date":430,"score":184,"percentile":431},"2026-01-26",0.17898,{"date":433,"score":184,"percentile":434},"2026-01-27",0.17885,{"date":436,"score":184,"percentile":437},"2026-01-28",0.1789,{"date":439,"score":184,"percentile":440},"2026-01-29",0.17865,{"date":442,"score":184,"percentile":443},"2026-01-30",0.17877,{"date":445,"score":184,"percentile":446},"2026-01-31",0.17889,{"date":448,"score":184,"percentile":449},"2026-02-01",0.17916,[451],{"source":140,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":452,"cvss_v4_0":9},{"baseScore":138,"baseSeverity":453,"vectorString":141,"impactScore":454,"exploitabilityScore":455},"MEDIUM",6,4.6,[457,489],{"ecosystem":9,"name":458,"vendor":459,"product":459,"cpe_part":460,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":461},"Linux","linux","a",[462,469,472,475,478,481,484,487],{"version":463,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":467,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C 1b6de5e6575b56502665c65cf93b0ae6aa0f51ab",true,"7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab","including","1b6de5e6575b56502665c65cf93b0ae6aa0f51ab","excluding",{"version":470,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":471,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C 9705f447bf9a6cd088300ad2c407b5e1c6591091","9705f447bf9a6cd088300ad2c407b5e1c6591091",{"version":473,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":474,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C 4318608dc28ef184158b4045896740716bea23f0","4318608dc28ef184158b4045896740716bea23f0",{"version":476,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":477,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C 7d0567842b78390dd9b60f00f1d8f838d540e325","7d0567842b78390dd9b60f00f1d8f838d540e325",{"version":479,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":480,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C f4877225313d474659ee53150ccc3d553a978727","f4877225313d474659ee53150ccc3d553a978727",{"version":482,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":483,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C e09cbe017311508c21e0739e97198a8388b98981","e09cbe017311508c21e0739e97198a8388b98981",{"version":485,"is_range":464,"range_type":146,"version_start":465,"version_start_type":466,"version_end":486,"version_end_type":468,"fixed_in":9},">= 7026b1ddb6b8d4e6ee33dc2bd06c0ca8746fa7ab, \u003C 18685451fc4e546fc0e718580d32df3c0e5c8272","18685451fc4e546fc0e718580d32df3c0e5c8272",{"version":488,"is_range":134,"range_type":146,"version_start":488,"version_start_type":466,"version_end":488,"version_end_type":466,"fixed_in":9},"4.1",{"ecosystem":9,"name":490,"vendor":459,"product":491,"cpe_part":492,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":493},"linux kernel","linux_kernel","o",[494,498,502,506,510,514,518],{"version":495,"is_range":464,"range_type":496,"version_start":488,"version_start_type":466,"version_end":497,"version_end_type":468,"fixed_in":9},"gte4.1_lt5.4.285","cpe","5.4.285",{"version":499,"is_range":464,"range_type":496,"version_start":500,"version_start_type":466,"version_end":501,"version_end_type":468,"fixed_in":9},"gte5.5_lt5.10.227","5.5","5.10.227",{"version":503,"is_range":464,"range_type":496,"version_start":504,"version_start_type":466,"version_end":505,"version_end_type":468,"fixed_in":9},"gte5.11_lt5.15.168","5.11","5.15.168",{"version":507,"is_range":464,"range_type":496,"version_start":508,"version_start_type":466,"version_end":509,"version_end_type":468,"fixed_in":9},"gte5.16_lt6.1.85","5.16","6.1.85",{"version":511,"is_range":464,"range_type":496,"version_start":512,"version_start_type":466,"version_end":513,"version_end_type":468,"fixed_in":9},"gte6.2_lt6.6.26","6.2","6.6.26",{"version":515,"is_range":464,"range_type":496,"version_start":516,"version_start_type":466,"version_end":517,"version_end_type":468,"fixed_in":9},"gte6.7_lt6.8.5","6.7","6.8.5",{"version":519,"is_range":134,"range_type":496,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.9:rc1"]