CVE-2024-26638 is a low-severity flaw in the Linux kernel's Network Block Device (NBD) driver, introduced in kernel version 5.19. Incomplete initialization of a struct msghdr in the NBD reply-receive path can expose the uninitialized msg_get_inq field during tcp_recvmsg processing, triggering a KMSAN uninitialized-value error and affecting system availability. Exploitation requires local access and high privileges; Red Hat assigns a CVSS 3.1 score of 4.4.
The upstream issue is fixed in Linux 6.1.76, 6.6.15, 6.7.3, 6.8, and later stable releases. Red Hat has issued fixes for affected Red Hat Enterprise Linux 8, RHEL 9, and RHEL 9.4 Extended Update Support packages, while RHEL 8 and RHEL 9 real-time kernels remain affected; unsupported RHEL 6 and 7 variants should be considered potentially affected. Organizations should update to vendor-supported current kernel releases rather than cherry-picking the individual upstream patch.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000, providing a fixed RHEL 8 kernel package for CVE-2024-26638.
Red Hat released RHSA-2025:9584, providing a fixed RHEL 9.4 Extended Update Support kernel package for CVE-2024-26638.
Red Hat released RHSA-2024:9315, providing a fixed RHEL 9 kernel package for CVE-2024-26638.
The Linux kernel CVE team documented fixes for the NBD flaw in Linux 6.1.76, 6.6.15, 6.7.3, and 6.8, which completely initialize struct msghdr. The team advised users to update to a current stable kernel release rather than cherry-pick individual commits.
A commit in Linux kernel 5.19 introduced incomplete initialization of struct msghdr in the NBD driver, allowing msg_get_inq to remain uninitialized during NBD reply reception.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.