Vulnerability advisory / 2024

CVE-2024-26855: NULL dereference in the Linux ice driver

An unchecked bridge attribute in ice_bridge_setlink() could reach nested attribute iteration as a NULL pointer.

Overview

The public Linux CVE record identifies a NULL-pointer dereference in ice_bridge_setlink(), part of the Intel ice network driver. The function looks for a bridge-specific netlink attribute using nlmsg_find_attr(). That lookup can return NULL.

The vulnerable path proceeded to nested attribute iteration using br_spec without first checking whether the attribute had been found. The fix validates br_spec before that iteration, preventing a missing attribute from becoming an invalid pointer access.

The correction was accepted into mainline Linux and backported to stable trees. The public record links the relevant kernel commits. Distribution packages may carry backported fixes, so assessing an installed system requires checking the vendor advisory as well as the upstream version.

This issue illustrates a code-review boundary worth checking: a parser lookup returning an optional value and a caller subsequently treating that value as guaranteed. The advisory records the public defect and correction without disclosing private discovery context.

Key facts

Vulnerability advisory
2024
Public record
Linux kernel · National Vulnerability Database
Affected code
Intel ice network driver · ice_bridge_setlink()
Topics
CVE-2024-26855 · Linux ice · NULL dereference · Code review
Primary source

Related work

08Contact

Let’s solve the next hard problem.

Tell me what you’re building, what is at stake and when you need a result. I’ll discuss the fit and propose a defined scope, deliverables and price.