---
id: CVE-2024-26642
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: nf_tables: disallow anonymous set with timeout flag

  Anonymous sets are never used with timeout from userspace, reject this.
  Exception to this rule is NFT_SE…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: nf_tables: disallow anonymous set with timeout flag

  Anonymous sets are never used with timeout from userspace, reject this.
  Exception to this rule is NFT_SE…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.1, < 4.19.312'
  - 'linux_kernel >= 4.20, < 5.4.274'
  - 'linux_kernel >= 5.5, < 5.10.215'
  - 'linux_kernel >= 5.11, < 5.15.154'
  - 'linux_kernel >= 5.16, < 6.1.84'
  - 'linux_kernel >= 6.2, < 6.6.24'
  - 'linux_kernel >= 6.7, < 6.7.12'
  - debian_linux = 10.0
patched:
  - linux_kernel 6.7.12
published: '2024-03-21'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26642'
references:
  - url: 'https://git.kernel.org/stable/c/16603605b667b70da974bea8216c93e7db043bf1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/72c1efe3f247a581667b7d368fff3bd9a03cd57a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7cdc1be24cc1bcd56a3e89ac4aef20e31ad09199'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8e07c16695583a66e81f67ce4c46e94dece47ba7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c0c2176d1814b92ea4c8e7eb7c9cd94cd99c1b12'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e4988d8415bd0294d6f9f4a1e7095f8b50a97ca9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e9a0d3f376eb356d54ffce36e7cc37514cbfbd6f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fe40ffbca19dc70d7c6b1e3c77b9ccb404c57351'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/16603605b667b70da974bea8216c93e7db043bf1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/72c1efe3f247a581667b7d368fff3bd9a03cd57a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/7cdc1be24cc1bcd56a3e89ac4aef20e31ad09199'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/8e07c16695583a66e81f67ce4c46e94dece47ba7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/c0c2176d1814b92ea4c8e7eb7c9cd94cd99c1b12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e4988d8415bd0294d6f9f4a1e7095f8b50a97ca9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e9a0d3f376eb356d54ffce36e7cc37514cbfbd6f'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/fe40ffbca19dc70d7c6b1e3c77b9ccb404c57351'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-265688.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00266
epssPercentile: 0.16478
ingestedAt: '2026-08-05T10:46:47.535Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: disallow anonymous set with timeout flag

Anonymous sets are never used with timeout from userspace, reject this.
Exception to this rule is NFT_SET_EVAL to ensure legacy meters still work.

## Affected

- `linux_kernel >= 4.1, < 4.19.312`
- `linux_kernel >= 4.20, < 5.4.274`
- `linux_kernel >= 5.5, < 5.10.215`
- `linux_kernel >= 5.11, < 5.15.154`
- `linux_kernel >= 5.16, < 6.1.84`
- `linux_kernel >= 6.2, < 6.6.24`
- `linux_kernel >= 6.7, < 6.7.12`
- `debian_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.12`
