🛡️ AZL-40497 — hyperv-daemons

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-26951 affecting package hyperv-daemons for versions less than 5.15.158.1-1

In the Linux kernel, the following vulnerability has been resolved:

wireguard: netlink: check for dangling peer via is_dead instead of empty list

If all peers are removed via wg_peer_remove_all(), rather than setting

peer_list to empty, the peer is added to a temporary list with a head on

the stack of wg_peer_remove_all(). If a netlink dump is resumed and the

cursored peer is one that has been removed via wg_peer_remove_all(), it

will iterate from that peer and then attempt to dump freed peers.

Fix this by instead checking peer->is_dead, which was explictly created

for this purpose. Also move up the device_update_lock lockdep assertion,

since reading is_dead relies on that.

It can be reproduced by a small script like:

echo "Setting config..."

ip link add dev wg0 type wireguard

wg setconf wg0 /big-config

(

while true; do

echo "Showing config..."

wg showconf wg0 > /dev/null

done

) &

sleep 4

wg setconf wg0 <(printf "[Peer]\nPublicKey=$(wg genkey)\n")

Resulting in:

BUG: KASAN: slab-use-after-free in __lock_acquire+0x182a/0x1b20

Read of size 8 at addr ffff88811956ec70 by task wg/59

CPU: 2 PID: 59 Comm: wg Not tainted 6.8.0-rc2-debug+ #5

Call Trace:

<TASK>

dump_stack_lvl+0x47/0x70

print_address_description.constprop.0+0x2c/0x380

print_report+0xab/0x250

kasan_report+0xba/0xf0

__lock_acquire+0x182a/0x1b20

lock_acquire+0x191/0x4b0

down_read+0x80/0x440

get_peer+0x140/0xcb0

wg_get_device_dump+0x471/0x1130

Affected software

AZL-40497 is recorded against 1 package.

  • hyperv-daemons (fixed in 5.15.158.1-1)

Timeline and source

Published on 1 May 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-05-01
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
hyperv-daemons 5.15.158.1-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-40497?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-40497 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.