cbcvebase.
CVE-2024-26621
published 2024-03-02

CVE-2024-26621: In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP boundaries") caused two issues [1] [2] reported on 32 bit system or compat userspace. It doesn't make too much sense to force huge page alignment on 32 bit system due to the constrained virtual address space. [1] https://lore.kernel.org/linux-mm/[email protected]/ [2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 87632bc9ecff5ded93433bc0fca428019bdd1cfe87632bc9ecff5ded93433bc0fca428019bdd1cfe
linuxlinux>= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 6ea9aa8d97e6563676094cb357558841732695556ea9aa8d97e6563676094cb35755884173269555
linuxlinux>= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 7432376c913381c5f24d373a87ff629bbde94b477432376c913381c5f24d373a87ff629bbde94b47
linuxlinux>= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 4ef9ad19e17676b9ef071309bc62020e2373705d4ef9ad19e17676b9ef071309bc62020e2373705d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 5.18 < 6.1.816.1.81
linuxlinux_kernel>= 6.2 < 6.6.466.6.46
linuxlinux_kernel>= 6.7 < 6.7.66.7.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.