
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-26668 affects the Linux kernel's netfilter component, specifically the nft_limit functionality. The vulnerability was discovered in January 2024 and involves an integer overflow issue in the token counter calculations. This vulnerability affects the netfilter subsystem when handling very large rate limit requests (around 17GB/s) (Kernel Git).
The vulnerability exists in the nft_limit.c file where internal token counter calculations could wrap around due to integer overflow. The issue occurs when processing configurations with very large rate limit requests, specifically around 17GB/s. The bug was introduced in commit d2168e849ebf which added per-byte limiting functionality (Kernel Git).
If exploited, this vulnerability could lead to incorrect rate limiting behavior in the netfilter subsystem. When the token counter wraps around due to very large requests, it could result in improper traffic control and potentially bypass intended rate limiting mechanisms (NVD).
The vulnerability requires the ability to configure netfilter rules with very large rate limit values (approximately 17GB/s). It primarily affects systems where users have the capability to set up netfilter rules with such extreme rate limiting configurations (Ubuntu).
The issue has been fixed in various Linux kernel versions through patches that implement proper overflow checking. The fix rejects bogus configurations where the internal token counter would wrap around, rather than allowing incorrect rate limiting to occur. Updates are available for multiple Linux distributions including Red Hat Enterprise Linux and Ubuntu (Red Hat, Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."