CVE-2024-26633

Local system crash via short fragment headers

Published Mar 18, 2024 · Updated May 23, 2026

Uninitialized-value use in the Linux kernel IPv6 tunnel parser allows local users to crash the system with short fragment headers. The ip6_tnl_parse_tlv_enc_lim() function reads frag_off after pulling only the IPv6 header into contiguous memory, without first ensuring that the fragment header is available. Low-privileged local access is required, and successful triggering interrupts availability without reported data disclosure or modification.

CVSS severity5.5
Medium
EPSS probability0.33%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Uninitialized-value use in the Linux kernel IPv6 tunnel parser allows local users to crash the system with short fragment headers. The ip6_tnl_parse_tlv_enc_lim() function reads frag_off after pulling only the IPv6 header into contiguous memory, without first ensuring that the fragment header is available. Low-privileged local access is required, and successful triggering interrupts availability without reported data disclosure or modification.

The record

CVE
CVE-2024-26633
Published
Mar 18, 2024
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
T1499.004
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Mar 18, 2024CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=3.10.106 <3.11
  2. Affected versionversion=3.12.71 <3.13
  3. Affected versionversion=3.16.42 <3.17
  4. Affected versionversion=3.18.49 <3.19
  5. Affected versionversion=3.2.87 <3.3
  6. Affected versionversion=4.10
  7. Affected versionversion=41e07a7e01d951cfd4c9a7dac90c921269d89513
  8. Affected versionversion=4.4.50 <4.5
  9. Affected versionversion=4.9.11 <4.10
  10. Affected versionversion=72bbf335e7aad09c88c50dbdd238f4faabd12174
  11. Affected versionversion=a6f6bb6bc04a5f88a31f47a6123d3fbf5ee8d694
  12. Affected versionversion=a7fe4e5d06338e1a82b1977eca37400951f99730
  13. Affected versionversion=d397f7035d2c754781bbe93b07b94d8cd898620c
  14. Affected versionversion=d3d9b59ab32160e3cc4edcf7e5fa7cecb53a7d25
  15. Affected versionversion=decccc92ee0a978a1c268b5df16824cb6384ed3c
  16. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <135414f300c5db995e2a2f3bf0f455de9d014aee
  17. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <3f15ba3dc14e6ee002ea01b4faddc3d49200377c
  18. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <4329426cf6b8e22b798db2331c7ef1dd2a9c748d
  19. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <62a1fedeb14c7ac0947ef33fadbabd35ed2400a2
  20. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <687c5d52fe53e602e76826dbd4d7af412747e183
  21. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <ba8d904c274268b18ef3dc11d3ca7b24a96cb087
  22. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <d375b98e0248980681e5e56b712026174d617198
  23. Affected versionversion=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <da23bd709b46168f7dfc36055801011222b076cd

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=3.10.106 <3.11; version=3.12.71 <3.13; version=3.16.42 <3.17; version=3.18.49 <3.19; version=3.2.87 <3.3; version=4.10; version=41e07a7e01d951cfd4c9a7dac90c921269d89513; version=4.4.50 <4.5; version=4.9.11 <4.10; version=72bbf335e7aad09c88c50dbdd238f4faabd12174; version=a6f6bb6bc04a5f88a31f47a6123d3fbf5ee8d694; version=a7fe4e5d06338e1a82b1977eca37400951f99730; version=d397f7035d2c754781bbe93b07b94d8cd898620c; version=d3d9b59ab32160e3cc4edcf7e5fa7cecb53a7d25; version=decccc92ee0a978a1c268b5df16824cb6384ed3c; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <135414f300c5db995e2a2f3bf0f455de9d014aee; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <3f15ba3dc14e6ee002ea01b4faddc3d49200377c; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <4329426cf6b8e22b798db2331c7ef1dd2a9c748d; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <62a1fedeb14c7ac0947ef33fadbabd35ed2400a2; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <687c5d52fe53e602e76826dbd4d7af412747e183; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <ba8d904c274268b18ef3dc11d3ca7b24a96cb087; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <d375b98e0248980681e5e56b712026174d617198; version=fbfa743a9d2a0ffa24251764f10afc13eb21e739 <da23bd709b46168f7dfc36055801011222b076cd

Published CVSS scores

5.5CanonicalCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

T1499.004Application or System Exploitation

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo