CVE-2024-26752

    Dashboard / Vulnerabilities / CVE-2024-26752

    CVE-2024-26752

    Published: 3 Apr 2024Last Modified: 8 Oct 2026

    Summary: l2tp: pass correct message length to ip6_append_data

    Details: In the Linux kernel, the following vulnerability has been resolved: l2tp: pass correct message length to ip6_append_data l2tp_ip6_sendmsg needs to avoid accounting for the transport header twice when splicing more data into an already partially-occupied skbuff. To manage this, we check whether the skbuff contains data using skb_queue_empty when deciding how much data to append using ip6_append_data. However, the code which performed the calculation was incorrect: ulen = len + skb_queue_empty(&sk->sk_write_queue) ? transhdrlen : 0; ...due to C operator precedence, this ends up setting ulen to transhdrlen for messages with a non-zero length, which results in corrupted packets on the wire. Add parentheses to correct the calculation in line with the original intent.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 559d697c5d072593d22b3e0bd8b8081108aeaf59

    Affected versions

    v4.19.307
    v4.19.306
    v4.19.305
    v4.19.304
    v4.19.303
    v4.19.302
    v4.19.301
    v4.19.300
    v4.19.299
    v4.19.298
    v4.19.297
    v4.19.296

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-26752 | CVE-DB