netlink: add nla be16/32 types to minlen array
Summary
| CVE | CVE-2024-26849 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-04-17 11:15:08 UTC |
| Updated | 2026-04-18 09:16:08 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline] BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline] BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631 nla_validate_range_unsigned lib/nlattr.c:222 [inline] nla_validate_int_range lib/nlattr.c:336 [inline] validate_nla lib/nlattr.c:575 [inline] ... The message in question matches this policy: [NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255), but because NLA_BE32 size in minlen array is 0, the validation code will read past the malformed (too small) attribute. Note: Other attributes, e.g. BITFIELD32, SINT, UINT.. are also missing: those likely should be added too. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-908
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 24ea1c8abaae6541ad95912422a9af4fb858428d 000a68159c0326b46c42ec712ab98793e7e625a7 git | Not specified |
| CNA | Linux | Linux | affected cbfac0add2afe8960a09806012313765a2179423 80b40f9cb87f3bf5877dfb852765cf92bc03ca77 git | Not specified |
| CNA | Linux | Linux | affected ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f 0ac219c4c3ab253f3981f346903458d20bacab32 git | Not specified |
| CNA | Linux | Linux | affected ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f a2ab028151841cd833cb53eb99427e0cc990112d git | Not specified |
| CNA | Linux | Linux | affected ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f 7a9d14c63b35f89563c5ecbadf918ad64979712d git | Not specified |
| CNA | Linux | Linux | affected ecaf75ffd5f5db320d8b1da0198eef5a5ce64a3f 9a0d18853c280f6a0ee99f91619f2442a17a323a git | Not specified |
| CNA | Linux | Linux | affected 6.1 | Not specified |
| CNA | Linux | Linux | unaffected 6.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.81 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.21 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.7.9 6.7.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.8 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/7a9d14c63b35f89563c5ecbadf918ad64979712d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/000a68159c0326b46c42ec712ab98793e7e625a7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/80b40f9cb87f3bf5877dfb852765cf92bc03ca77 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9a0d18853c280f6a0ee99f91619f2442a17a323a | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/0ac219c4c3ab253f3981f346903458d20bacab32 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/a2ab028151841cd833cb53eb99427e0cc990112d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.