cve/2024/CVE-2024-26634.md
2024-05-25 21:48:12 +02:00

1.1 KiB

CVE-2024-26634

Description

In the Linux kernel, the following vulnerability has been resolved:net: fix removing a namespace with conflicting altnamesMark reports a BUG() when a net namespace is removed. kernel BUG at net/core/dev.c:11520!Physical interfaces moved outside of init_net get "refunded"to init_net when that namespace disappears. The main interfacename may get overwritten in the process if it would haveconflicted. We need to also discard all conflicting altnames.Recent fixes addressed ensuring that altnames get movedwith the main interface, which surfaced this problem.

POC

Reference

No PoCs from references.

Github