CVE-2024-26633 is a Linux kernel vulnerability affecting the ip6_tunnel module, specifically in the ip6_tnl_parse_tlv_enc_lim() function. It stems from incorrect handling of NEXTHDR_FRAGMENT, leading to potential access of uninitialized memory when reading frag_off. This issue impacts Debian, Linux, and NetApp products. The vulnerability is rated Medium (CVSS 5.5) with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating it requires local access and low attack complexity. Its primary impact is a high availability risk (A:H), suggesting it could lead to system crashes or denial of service. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.10, < 4.19.306CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.268CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.209CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.148CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.75CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.