CVE-2024-26621
published 2024-03-02CVE-2024-26621: In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
mm: huge_memory: don't force huge page alignment on 32 bit
commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP
boundaries") caused two issues [1] [2] reported on 32 bit system or compat
userspace.
It doesn't make too much sense to force huge page alignment on 32 bit
system due to the constrained virtual address space.
[1] https://lore.kernel.org/linux-mm/[email protected]/
[2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.82-1 (bookworm) | linux 6.1.82-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 87632bc9ecff5ded93433bc0fca428019bdd1cfe | 87632bc9ecff5ded93433bc0fca428019bdd1cfe |
| linux | linux | >= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 6ea9aa8d97e6563676094cb35755884173269555 | 6ea9aa8d97e6563676094cb35755884173269555 |
| linux | linux | >= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 7432376c913381c5f24d373a87ff629bbde94b47 | 7432376c913381c5f24d373a87ff629bbde94b47 |
| linux | linux | >= 1854bc6e2420472676c5c90d3d6b15f6cd640e40 < 4ef9ad19e17676b9ef071309bc62020e2373705d | 4ef9ad19e17676b9ef071309bc62020e2373705d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.82-1 | 6.1.82-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 5.18 < 6.1.81 | 6.1.81 |
| linux | linux_kernel | >= 6.2 < 6.6.46 | 6.6.46 |
| linux | linux_kernel | >= 6.7 < 6.7.6 | 6.7.6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pv98-48f2-5vjr: In the Linux kernel, the following vulnerability has been resolved:
mm: huge_memory: don't force huge page alignment on 32 bit
commit efa7df3e3bb5 (
ghsa_unreviewed·2024-03-03
CVE-2024-26621 [MEDIUM] GHSA-pv98-48f2-5vjr: In the Linux kernel, the following vulnerability has been resolved:
mm: huge_memory: don't force huge page alignment on 32 bit
commit efa7df3e3bb5 (
In the Linux kernel, the following vulnerability has been resolved:
mm: huge_memory: don't force huge page alignment on 32 bit
commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP
boundaries") caused two issues [1] [2] reported on 32 bit system or compat
userspace.
It doesn't make too much sense to force huge page alignment on 32 bit
system due to the constrained virtual address space.
[1] https://lore.kernel.org/linux-mm/[email protected]/
[2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/
OSV
CVE-2024-26621: In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("m
osv·2024-03-02·CVSS 5.5
CVE-2024-26621 [MEDIUM] CVE-2024-26621: In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("m
In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP boundaries") caused two issues [1] [2] reported on 32 bit system or compat userspace. It doesn't make too much sense to force huge page alignment on 32 bit system due to the constrained virtual address space. [1] https://lore.kernel.org/linux-mm/[email protected]/ [2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/
Red Hat
kernel: mm: huge_memory: don't force huge page alignment on 32 bit
vendor_redhat·2024-03-02·CVSS 5.5
CVE-2024-26621 [MEDIUM] CWE-99 kernel: mm: huge_memory: don't force huge page alignment on 32 bit
kernel: mm: huge_memory: don't force huge page alignment on 32 bit
In the Linux kernel, the following vulnerability has been resolved:
mm: huge_memory: don't force huge page alignment on 32 bit
commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP
boundaries") caused two issues [1] [2] reported on 32 bit system or compat
userspace.
It doesn't make too much sense to force huge page alignment on 32 bit
system due to the constrained virtual address space.
[1] https://lore.kernel.org/linux-mm/[email protected]/
[2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
P
Debian
CVE-2024-26621: linux - In the Linux kernel, the following vulnerability has been resolved: mm: huge_me...
vendor_debian·2024·CVSS 5.5
CVE-2024-26621 [MEDIUM] CVE-2024-26621: linux - In the Linux kernel, the following vulnerability has been resolved: mm: huge_me...
In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP boundaries") caused two issues [1] [2] reported on 32 bit system or compat userspace. It doesn't make too much sense to force huge page alignment on 32 bit system due to the constrained virtual address space. [1] https://lore.kernel.org/linux-mm/[email protected]/ [2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/
Scope: local
bookworm: resolved (fixed in 6.1.82-1)
bullseye: resolved
forky: resolved (fixed in 6.7.7-1)
sid: resolved (fixed in 6.7.7-1)
trixie: resolved (fixed in 6.7.7-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/4ef9ad19e17676b9ef071309bc62020e2373705dhttps://git.kernel.org/stable/c/6ea9aa8d97e6563676094cb35755884173269555https://git.kernel.org/stable/c/7432376c913381c5f24d373a87ff629bbde94b47https://git.kernel.org/stable/c/87632bc9ecff5ded93433bc0fca428019bdd1cfehttp://www.openwall.com/lists/oss-security/2024/07/08/3http://www.openwall.com/lists/oss-security/2024/07/08/4http://www.openwall.com/lists/oss-security/2024/07/08/5http://www.openwall.com/lists/oss-security/2024/07/08/6http://www.openwall.com/lists/oss-security/2024/07/08/7http://www.openwall.com/lists/oss-security/2024/07/08/8http://www.openwall.com/lists/oss-security/2024/07/09/1http://www.openwall.com/lists/oss-security/2024/07/10/5http://www.openwall.com/lists/oss-security/2024/07/10/7http://www.openwall.com/lists/oss-security/2024/07/10/8http://www.openwall.com/lists/oss-security/2024/07/11/4http://www.openwall.com/lists/oss-security/2024/07/11/5http://www.openwall.com/lists/oss-security/2024/07/11/7http://www.openwall.com/lists/oss-security/2024/07/12/3http://www.openwall.com/lists/oss-security/2024/07/13/2http://www.openwall.com/lists/oss-security/2024/07/13/7http://www.openwall.com/lists/oss-security/2024/07/15/1http://www.openwall.com/lists/oss-security/2024/07/15/2http://www.openwall.com/lists/oss-security/2024/07/16/1http://www.openwall.com/lists/oss-security/2024/07/16/2http://www.openwall.com/lists/oss-security/2024/07/29/2http://www.openwall.com/lists/oss-security/2024/07/30/2https://git.kernel.org/stable/c/4ef9ad19e17676b9ef071309bc62020e2373705dhttps://git.kernel.org/stable/c/7432376c913381c5f24d373a87ff629bbde94b47https://git.kernel.org/stable/c/87632bc9ecff5ded93433bc0fca428019bdd1cfehttps://zolutal.github.io/aslrnt/
2024-03-02
Published