CVE-2024-26855
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-26855 is a vulnerability in the Linux kernel's ice_bridge_setlink() function. The vulnerability was discovered on April 17, 2024, affecting various versions of the Linux kernel from 4.20 up to versions before 5.4.272, 5.10.213, 5.15.152, and 6.1.82. The issue involves a potential NULL pointer dereference in the ice_bridge_setlink() function when nlmsg_find_attr() returns NULL and br_spec is dereferenced subsequently in nla_for_each_nested() (NVD).

Technical details

The vulnerability is classified as a NULL Pointer Dereference (CWE-476) with a CVSS v3.1 Base Score of 5.5 (Medium). The issue occurs in the Linux kernel's networking subsystem, specifically in the Intel ICE driver's bridge functionality. The vulnerability manifests when the ice_bridge_setlink() function fails to properly validate the return value from nlmsg_find_attr() before using it in a nested attribute iteration (NVD, Kernel Patch).

Impact

The vulnerability could lead to a denial of service condition through a NULL pointer dereference. The attack requires local access and low privileges to exploit, with the potential impact primarily affecting system availability rather than confidentiality or integrity (NVD).

Exploitability

The vulnerability requires local access with low privileges and no user interaction to exploit. The attack complexity is rated as low, indicating relatively straightforward exploitation conditions (NVD).

Mitigation and workarounds

The vulnerability has been patched in the Linux kernel by adding a check to ensure that br_spec is not NULL before proceeding with the nested attribute iteration. The fix has been backported to multiple kernel versions and is available in various distribution updates including Ubuntu and Debian (Kernel Patch, Debian).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68422NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68399NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68398NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68376NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68374NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management