Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-26853

9.8 · CRITICAL
Published Apr 17, 2024 linux CWE-787 EPSS 0.63% (48th pctl)

Overview

CVE-2024-26853 is a critical-severity vulnerability affecting linux linux_kernel. It was published on April 17, 2024 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

igc: avoid returning frame twice in XDP_REDIRECT

When a frame can not be transmitted in XDP_REDIRECT

(e.g. due to a full queue), it is necessary to free

it by calling xdp_return_frame_rx_napi.

However, this is the responsibility of the caller of

the ndo_xdp_xmit (see for example bq_xmit_all in

kernel/bpf/devmap.c) and thus calling it inside

igc_xdp_xmit (which is the ndo_xdp_xmit of the igc

driver) as well will lead to memory corruption.

In fact, bq_xmit_all expects that it can return all

frames after the last successfully transmitted one.

Therefore, break for the first not transmitted frame,

but do not call xdp_return_frame_rx_napi in igc_xdp_xmit.

This is equally implemented in other Intel drivers

such as the igb.

There are two alternatives to this that were rejected:

1. Return num_frames as all the frames would have been

transmitted and release them inside igc_xdp_xmit.

While it might work technically, it

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.13, < 6.1.82 Affected

Frequently Asked Questions

What is CVE-2024-26853?

CVE-2024-26853 is a critical-severity vulnerability affecting linux linux_kernel. It was published on April 17, 2024 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

How severe is CVE-2024-26853?

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-26853?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-26853?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-26853 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.