CVE-2024-26834
Published: Apr 17, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: release dst in case direct xmit path is used Direct xmit does not use it since it calls dev_queue_xmit() to send packets, hence it calls dst_release(). kmemleak reports: unreferenced object 0xffff88814f440900 (size 184): comm "softirq", pid 0, jiffies 4294951896 hex dump (first 32 bytes): 00 60 5b 04 81 88 ff ff 00 e6 e8 82 ff ff ff ff .`[............. 21 0b 50 82 ff ff ff ff 00 00 00 00 00 00 00 00 !.P............. backtrace (crc cb2bf5d6): [<000000003ee17107>] kmem_cache_alloc+0x286/0x340 [<0000000021a5de2c>] dst_alloc+0x43/0xb0 [<00000000f0671159>] rt_dst_alloc+0x2e/0x190 [<00000000fe5092c9>] __mkroute_output+0x244/0x980 [<000000005fb96fb0>] ip_route_output_flow+0xc0/0x160 [<0000000045367433>] nf_ip_route+0xf/0x30 [<0000000085da1d8e>] nf_route+0x2d/0x60 [<00000000d1ecd1cb>] nft_flow_route+0x171/0x6a0 [nft_flow_offload] [<00000000d9b2fb60>] nft_flow_offload_eval+0x4e8/0x700 [nft_flow_offload] [<000000009f447dbb>] expr_call_ops_eval+0x53/0x330 [nf_tables] [<00000000072e1be6>] nft_do_chain+0x17c/0x840 [nf_tables] [<00000000d0551029>] nft_do_chain_inet+0xa1/0x210 [nf_tables] [<0000000097c9d5c6>] nf_hook_slow+0x5b/0x160 [<0000000005eccab1>] ip_forward+0x8b6/0x9b0 [<00000000553a269b>] ip_rcv+0x221/0x230 [<00000000412872e5>] __netif_receive_skb_one_core+0xfe/0x110
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 7c71b831220edeab7ce603d818dc1708d9ea4137 - < 13b57b5cd591d5b22f9bbf047b2922967de411f3affected 9c5662e95a8dcc232c3ef4deb21033badcd260f6 - < a6cafdb49a7bbf4a88367db209703eee6941e023affected fa502c86566680ac62bc28ec883a069bf7a2aa5e - < 9256ab9232e35a16af9c30fa4e522e6d1bd3605aaffected fa502c86566680ac62bc28ec883a069bf7a2aa5e - < 2d17cf10179a7de6d8f0128168b84ad0b4a1863faffected fa502c86566680ac62bc28ec883a069bf7a2aa5e - < 8762785f459be1cfe6fcf7285c123aad6a3703f0 |
Linux | Linux | affected 6.5unaffected 0 - < 6.5unaffected 6.6.19 - <= 6.6.*unaffected 6.7.7 - <= 6.7.*unaffected 6.8 - <= * |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now