cbcvebase.
CVE-2024-26602
published 2024-02-26

CVE-2024-26602: In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
23.9th percentile
In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems, sys_membarrier can be very expensive, causing overall slowdowns for everything. So put a lock on the path in order to serialize the accesses to prevent the ability for this to be called at too high of a frequency and saturate the machine.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < 3cd139875e9a7688b3fc715264032620812a5fa33cd139875e9a7688b3fc715264032620812a5fa3
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < 2441a64070b85c14eecc3728cc87e883f953f2652441a64070b85c14eecc3728cc87e883f953f265
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < db896bbe4a9c67cee377e5f6a743350d3ae4acf6db896bbe4a9c67cee377e5f6a743350d3ae4acf6
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < 50fb4e17df319bb33be6f14e2a856950c1577dee50fb4e17df319bb33be6f14e2a856950c1577dee
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < 24ec7504a08a67247fbe798d1de995208a8c128a24ec7504a08a67247fbe798d1de995208a8c128a
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < b6a2a9cbb67545c825ec95f06adb7ff300a2ad71b6a2a9cbb67545c825ec95f06adb7ff300a2ad71
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < c5b2063c65d05e79fad8029324581d86cfba7eeac5b2063c65d05e79fad8029324581d86cfba7eea
linuxlinux>= 22e4ebb975822833b083533035233d128b30e98f < 944d5fe50f3f03daacfea16300e656a1691c4a23944d5fe50f3f03daacfea16300e656a1691c4a23
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 4.14.0 < 4.19.3074.19.307
linuxlinux_kernel>= 4.20.0 < 5.4.2695.4.269
linuxlinux_kernel>= 5.11.0 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16.0 < 6.1.796.1.79
linuxlinux_kernel>= 5.5.0 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2.0 < 6.6.186.6.18
linuxlinux_kernel>= 6.7.0 < 6.7.66.7.6
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.7MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.