VDB
ALSA-2024%3A3306
ALSA-2024%3A3306
PUBLISHED
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout (CVE-2024-26643) * kernel: netfilter: nf_tables: disallow anonymous set with timeout flag (CVE-2024-26642) * kernel: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations (CVE-2024-26673) * kernel: net: ip_tunnel: prevent perpetual headroom growth (CVE-2024-26804)
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | kernel-rt-debug-devel | 0, 0 |
| AlmaLinux:9 | kernel-devel-matched | 0, 0 |
| AlmaLinux:9 | kernel-rt-debug | 0, 0 |
| AlmaLinux:9 | perf | 0, 0 |
| AlmaLinux:9 | kernel-debug-modules-core | 0, 0 |
| AlmaLinux:9 | kernel-64k-devel-matched | 0, 0 |
| AlmaLinux:9 | kernel-64k-modules-core | 0, 0 |
| AlmaLinux:9 | kernel-rt-devel | 0, 0 |
| AlmaLinux:9 | kernel-64k-modules-extra | 0, 0 |
| AlmaLinux:9 | kernel-64k-core | 0, 0 |
| AlmaLinux:9 | rtla | 0, 0 |
| AlmaLinux:9 | kernel-rt-debug-core | 0, 0 |
| AlmaLinux:9 | kernel-modules | 0, 0 |
| AlmaLinux:9 | libperf | 0, 0 |
| AlmaLinux:9 | kernel | 0, 0 |
| AlmaLinux:9 | kernel-rt | 0, 0 |
| AlmaLinux:9 | kernel-64k-debug-core | 0, 0 |
| AlmaLinux:9 | kernel-rt-debug-modules-extra | 0, 0 |
| AlmaLinux:9 | kernel-zfcpdump-devel-matched | 0, 0 |
| AlmaLinux:9 | kernel-devel | 0, 0 |
…and 42 more
Timeline
- May 23, 2024 CVE Published
- Nov 3, 2024 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:3306 vendor-advisory
- https://bugzilla.redhat.com/2270879 third-party-advisory
- https://bugzilla.redhat.com/2270881 third-party-advisory
- https://bugzilla.redhat.com/2272816 third-party-advisory
- https://bugzilla.redhat.com/2273423 third-party-advisory
- https://errata.almalinux.org/9/ALSA-2024-3306.html vendor-advisory
- https://www.redhat.com/security/data/cve/CVE-2024-26642.html third-party-advisory
- https://www.redhat.com/security/data/cve/CVE-2024-26643.html third-party-advisory
- https://www.redhat.com/security/data/cve/CVE-2024-26673.html third-party-advisory
- https://www.redhat.com/security/data/cve/CVE-2024-26804.html third-party-advisory
- https://www.redhat.com/security/data/cve/CVE-2024-35890.html third-party-advisory