cbcvebase.
CVE-2024-26618
published 2024-03-11

CVE-2024-26618: In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with existing storage When sme_alloc() is called…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with existing storage When sme_alloc() is called with existing storage and we are not flushing we will always allocate new storage, both leaking the existing storage and corrupting the state. Fix this by separating the checks for flushing and for existing storage as we do for SVE. Callers that reallocate (eg, due to changing the vector length) should call sme_free() themselves.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 21614ba60883eb93b99a7ee4b41cb927f93b39ae < f6421555dbd7cb3d4d70b69f33f998aaeca1e3b5f6421555dbd7cb3d4d70b69f33f998aaeca1e3b5
linuxlinux>= 5d0a8d2fba50e9c07cde4aad7fba28c008b07a5b < 569156e4fa347237f8fa2a7e935d860109c55ac4569156e4fa347237f8fa2a7e935d860109c55ac4
linuxlinux>= 5d0a8d2fba50e9c07cde4aad7fba28c008b07a5b < 814af6b4e6000e574e74d92197190edf07cc3680814af6b4e6000e574e74d92197190edf07cc3680
linuxlinux>= 5d0a8d2fba50e9c07cde4aad7fba28c008b07a5b < dc7eb8755797ed41a0d1b5c0c39df3c8f401b3d9dc7eb8755797ed41a0d1b5c0c39df3c8f401b3d9
linuxlinux>= 6.1.47 < 6.1.1406.1.140
linuxlinux>= 6.4.12 < 6.56.5
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 6.5 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.