CVE-2024-26809
Published: Apr 4, 2024
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: release elements in clone only from destroy path Clone already always provides a current view of the lookup table, use it to destroy the set, otherwise it is possible to destroy elements twice. This fix requires: 212ed75dc5fb ("netfilter: nf_tables: integrate pipapo into commit protocol") which came after: 9827a0e6e23b ("netfilter: nft_set_pipapo: release elements in clone from abort path").
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 4a6430b99f67842617c7208ca55a411e903ba03a - < b36b83297ff4910dfc8705402c8abffd4bbf8144affected 5ccecafc728b0df48263d5ac198220bcd79830bc - < 362508506bf545e9ce18c72a2c48dcbfb891ab9caffected 9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e - < 5ad233dc731ab64cdc47b84a5c1f78fff6c024afaffected 9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e - < ff90050771412b91e928093ccd8736ae680063c2affected 9827a0e6e23bf43003cd3d5b7fb11baf59a35e1e - < 821e28d5b506e6a73ccc367ff792bd894050d48b+6 more versions |
Linux | Linux | affected 5.19unaffected 0 - < 5.19unaffected 5.10.214 - <= 5.10.*unaffected 5.15.153 - <= 5.15.*unaffected 6.1.83 - <= 6.1.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now