CVE-2024-26804 is a use-after-free flaw in the Linux kernel's IPv4 ip_tunnel infrastructure that allows a low-privileged local user to crash an affected system. Recursive GRE or IPIP tunnel routing can cause a tunnel device's needed_headroom to increase indefinitely; after the packet buffer headroom exceeds 64 KiB, the 16-bit skb->network_header field can wrap, resulting in an out-of-bounds packet-buffer adjustment and use-after-free condition.
The issue has existed since kernel version 2.6.34 and is fixed in stable releases 5.4.271, 5.10.212, 5.15.151, 6.1.81, 6.6.21, 6.7.9, and 6.8 or later. Red Hat rates the issue as moderate severity with CVSS 5.5 and has issued updates for affected RHEL 8 and 9 streams; RHEL 6 is unsupported and should be considered affected. Organizations should deploy vendor kernel updates or move to a current stable kernel release rather than cherry-picking the individual patch.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:4352, providing RHEL 8 kernel-rt updates that fix CVE-2024-26804.
Red Hat issued RHSA-2024:4211 with RHEL 8 kernel updates that remediate CVE-2024-26804.
RHSA-2024:3461 and RHSA-2024:3460 provided kernel and kernel-rt fixes, respectively, for Red Hat Enterprise Linux 9.2 Extended Update Support.
Red Hat released RHSA-2024:3306, providing RHEL 9 kernel updates that fix CVE-2024-26804.
Red Hat issued RHSA-2024:4740 to fix CVE-2024-26804 in the RHEL 8.8 Extended Update Support stream.
RHSA-2024:4447 delivered fixes for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
The Linux kernel CVE team assigned CVE-2024-26804 to the IPv4 IP-tunnel issue. Fixes that cap needed_headroom growth were included in stable kernel releases 5.4.271, 5.10.212, 5.15.151, 6.1.81, 6.6.21, 6.7.9, and 6.8.
The perpetual IP-tunnel headroom-growth flaw was introduced in Linux kernel 2.6.34 by commit 243aad830e8a. Recursive GRE and IPIP routing could ultimately trigger an out-of-bounds skb adjustment and use-after-free.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.