kernel CVE-2024-26581
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.19.3
Patched versions
1.19.3
kernel-5.15
(bottlerocket)
< 1.19.3
1.19.3
kernel-6.1
(bottlerocket)
< 1.19.3
1.19.3
A flaw was found in the Linux kernel’s Netfilter subsystem. This issue occurs in the nft_set_rbtree. rbtree lazy gc on insert, which might collect an end interval element just added in a transaction and skip the end interval elements not yet active.