
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-26855 is a vulnerability in the Linux kernel's ice_bridge_setlink() function. The vulnerability was discovered on April 17, 2024, affecting various versions of the Linux kernel from 4.20 up to versions before 5.4.272, 5.10.213, 5.15.152, and 6.1.82. The issue involves a potential NULL pointer dereference in the ice_bridge_setlink() function when nlmsg_find_attr() returns NULL and br_spec is dereferenced subsequently in nla_for_each_nested() (NVD).
The vulnerability is classified as a NULL Pointer Dereference (CWE-476) with a CVSS v3.1 Base Score of 5.5 (Medium). The issue occurs in the Linux kernel's networking subsystem, specifically in the Intel ICE driver's bridge functionality. The vulnerability manifests when the ice_bridge_setlink() function fails to properly validate the return value from nlmsg_find_attr() before using it in a nested attribute iteration (NVD, Kernel Patch).
The vulnerability could lead to a denial of service condition through a NULL pointer dereference. The attack requires local access and low privileges to exploit, with the potential impact primarily affecting system availability rather than confidentiality or integrity (NVD).
The vulnerability requires local access with low privileges and no user interaction to exploit. The attack complexity is rated as low, indicating relatively straightforward exploitation conditions (NVD).
The vulnerability has been patched in the Linux kernel by adding a check to ensure that br_spec is not NULL before proceeding with the nested attribute iteration. The fix has been backported to multiple kernel versions and is available in various distribution updates including Ubuntu and Debian (Kernel Patch, Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."