CVE-2024-26723·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix crash when adding interface under a lag There is a crash when adding one of the lan966x interfaces under a lag interface. The issue can be reproduced like this: ip link add name bond0 type bond miimon 100 mode balance-xor ip link set dev eth0 master bond0 The reason is because when adding a interface under the lag it would go through all the ports and try to figure out which other ports are under that lag interface. And the issue is that lan966x can have ports that are NULL pointer as they are not probed. So then iterating over these ports it would just crash as they are NULL pointers. The fix consists in actually checking for NULL pointers before accessing something from the ports. Like we do in other places.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.7.6
- Published
- 2024-04-03
Affected versions
From: 6.7
Until: 6.7.6
Fixed in: 6.7.6
How to fix this CVE
Update your Linux kernel to version 6.7.6 or later to resolve a critical null pointer dereference that occurs when bonding LAN966x network interfaces. This patch adds proper null pointer validation during LAG (Link Aggregation Group) interface operations, preventing kernel crashes when configuring bonded connections. Apply the update immediately if you are running kernel versions 6.7 through 6.7.5 and use LAN966x network adapters.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version with: uname -r — vulnerable if output shows 6.7.0 through 6.7.5
- Verify if LAN966x drivers are loaded: lsmod | grep lan966x — if output is empty, this vulnerability does not apply to your system
- Test LAG bonding configuration on LAN966x interfaces with: ip link add name bond0 type bond miimon 100 mode balance-xor && ip link set dev eth0 master bond0 — if this command causes a kernel panic or system crash, the vulnerability is present
- After patching, confirm the new kernel version is active: uname -r — should show 6.7.6 or later
FAQ
What is CVE-2024-26723?
A null pointer dereference vulnerability in the Linux kernel's LAN966x network driver that crashes the system when attempting to add a network interface to a bonded LAG configuration. The driver fails to validate that all port structures are properly initialized before accessing them during LAG membership operations.
Is CVE-2024-26723 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, it can be trivially triggered by any local user with network configuration privileges.
What versions of Kernel are affected by CVE-2024-26723?
Linux kernel versions 6.7.0 through 6.7.5 are vulnerable. Kernel 6.7.6 and all later versions include the fix.
How do I check if my server is vulnerable to CVE-2024-26723?
Run: uname -r && lsmod | grep lan966x — your system is vulnerable only if the kernel version is between 6.7.0-6.7.5 AND the lan966x module is loaded.
Does Defensia detect CVE-2024-26723?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-26723 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/15faa1f67ab405d47789d4702f587ec7df7ef03e
- https://git.kernel.org/stable/c/2a492f01228b7d091dfe38974ef40dccf8f9f2f1
- https://git.kernel.org/stable/c/48fae67d837488c87379f0c9f27df7391718477c
- https://git.kernel.org/stable/c/b9357489c46c7a43999964628db8b47d3a1f8672
- https://git.kernel.org/stable/c/15faa1f67ab405d47789d4702f587ec7df7ef03e
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-26723. Free for 1 server.
Get started free