CVE-2024-26614Improper Locking in Linux

Severity
5.5MEDIUMNVD
OSV6.5OSV4.3
EPSS
0.0%
top 99.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11
Latest updateJun 11

Description

In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following issue: pvqspinlock: lock 0xffff9d181cd5c660 has corrupted value 0x0! WARNING: CPU: 19 PID: 21160 at __pv_queued_spin_unlock_slowpath (kernel/locking/qspinlock_paravirt.h:508) Hardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011 RIP: 0010:__pv_queued_spin_unlock_slowpath (kernel/locking/qspinlock_paravirt.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel3.75.10.210+5
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-182.202+3
CVEListV5linux/linux168a8f58059a22feb9e9a2dcc1b8053dbbbc12efbc99dcedd2f422d602516762b96c8ef1ae6b2882+6
debiandebian/linux< linux 6.1.76-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

15
OSV
linux-intel-iotg-5.15 vulnerabilities2024-06-11
OSV
linux-intel-iotg vulnerabilities2024-05-28
OSV
linux-aws-hwe vulnerabilities2024-05-23
OSV
linux-gcp vulnerabilities2024-05-21
OSV
linux-aws, linux-aws-5.15 vulnerabilities2024-05-20

📋Vendor Advisories

14
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-06-11
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-05-28
Ubuntu
Linux kernel (HWE) vulnerabilities2024-05-23
Ubuntu
Linux kernel (GCP) vulnerabilities2024-05-21
Ubuntu
Linux kernel (Azure) vulnerabilities2024-05-20

💬Community

1
Bugzilla
CVE-2024-26614 kernel: tcp: make sure init the accept_queue&#39;s spinlocks once2024-03-12