PT-2026-64796 · Linux · Linux Kernel

CVE-2024-14040

·

Published

2026-07-26

·

Updated

2026-08-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In CLOS networks, Equal-Cost Multi-Path (ECMP) weights are adjusted to compensate for link failures. In deployments with high fan-out and a large number of nodes, the 8-bit weight limit is insufficient for configuring required weight ratios. To address this, the next hop weight was increased from u8 to u16. The UAPI for configuring nexthop group members uses the NHA GROUP attribute, which contains an array of nexthop grp structures. The resvd1 field in this structure was repurposed as weight high to carry the high-order bits of the weight, ensuring compatibility with older userspace and avoiding endianness issues.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-93953
CVE-2024-14040

Affected Products

Linux Kernel