---
id: CVE-2024-26739
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/sched: act_mirred: don't override retval if we already lost the skb

  If we're redirecting the skb, and haven't called tcf_mirred_forward(),
  yet, we need to tell the…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/sched: act_mirred: don't override retval if we already lost the skb

  If we're redirecting the skb, and haven't called tcf_mirred_forward(),
  yet, we need to tell the…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: debian
product: debian_linux
affected:
  - debian_linux = 11.0
  - 'linux_kernel >= 4.19, < 5.10.238'
  - 'linux_kernel >= 5.11, < 5.15.182'
  - 'linux_kernel >= 5.16, < 6.1.136'
  - 'linux_kernel >= 6.2, < 6.6.19'
  - 'linux_kernel >= 6.7, < 6.7.7'
  - linux_kernel = 6.8
patched:
  - linux_kernel 6.7.7
published: '2024-04-03'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26739'
references:
  - url: 'https://git.kernel.org/stable/c/0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9d3ef89b6a5e9f2e940de2cef3d543be0be8dec5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e873e8f7d03a2ee5b77fb1a305c782fed98e2754'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00278
epssPercentile: 0.18088
ingestedAt: '2026-08-05T10:46:48.392Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_mirred: don't override retval if we already lost the skb

If we're redirecting the skb, and haven't called tcf_mirred_forward(),
yet, we need to tell the core to drop the skb by setting the retcode
to SHOT. If we have called tcf_mirred_forward(), however, the skb
is out of our hands and returning SHOT will lead to UaF.

Move the retval override to the error path which actually need it.

## Affected

- `debian_linux = 11.0`
- `linux_kernel >= 4.19, < 5.10.238`
- `linux_kernel >= 5.11, < 5.15.182`
- `linux_kernel >= 5.16, < 6.1.136`
- `linux_kernel >= 6.2, < 6.6.19`
- `linux_kernel >= 6.7, < 6.7.7`
- `linux_kernel = 6.8`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.7`
