Wind River Support Network

HomeDefectsLIN1023-4289
Fixed

LIN1023-4289 : Security Advisory - linux - CVE-2024-26634

Created: Mar 18, 2024    Updated: Apr 20, 2024
Resolved Date: Apr 19, 2024
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net: fix removing a namespace with conflicting altnames

Mark reports a BUG() when a net namespace is removed.

    kernel BUG at net/core/dev.c:11520!

Physical interfaces moved outside of init_net get "refunded"
to init_net when that namespace disappears. The main interface
name may get overwritten in the process if it would have
conflicted. We need to also discard all conflicting altnames.
Recent fixes addressed ensuring that altnames get moved
with the main interface, which surfaced this problem.

CREATE(Triage):(User=admin) CVE-2024-26634 (https://nvd.nist.gov/vuln/detail/CVE-2024-26634)

CVEs


Live chat
Online