CVE-2024-26665 is an out-of-bounds read vulnerability in Linux kernel tunnel handling. When constructing an ICMPv6 IPv6 Path MTU (PMTU) error from a non-linear socket buffer, the affected code invokes csum_partial(), which cannot safely process non-linear SKBs. This can cause a KASAN-detected slab out-of-bounds read during checksum processing. The vulnerable path includes iptunnel_pmtud_build_icmpv6(), skb_tunnel_check_pmtu(), and VXLAN transmission. The upstream correction uses skb_checksum() to calculate the checksum safely for non-linear packet buffers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel vulnerability covered by the security update.
Linux kernel tunnel IPv6 PMTU error-processing out-of-bounds access flaw.
Out-of-bounds access in Linux kernel tunnel handling while building IPv6 PMTU errors.
An out-of-bounds access vulnerability in the Linux kernel tunnel code while constructing IPv6 Path MTU (PMTU) ICMPv6 error packets. The fix replaces a direct partial checksum calculation with skb_checksum(), accounting for the packet buffer layout.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.