cbcvebase.
CVE-2024-26622
published 2024-03-04

CVE-2024-26622: In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control() Since tomoyo_write_control() updates…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control() Since tomoyo_write_control() updates head->write_buf when write() of long lines is requested, we need to fetch head->write_buf after head->io_sem is held. Otherwise, concurrent write() requests can cause use-after-free-write and double-free problems.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= bd03a3e4c9a9df0c6b007045fa7fc8889111a478 < a23ac1788e2c828c097119e9a3178f0b7e503feea23ac1788e2c828c097119e9a3178f0b7e503fee
linuxlinux>= bd03a3e4c9a9df0c6b007045fa7fc8889111a478 < 7d930a4da17958f869ef679ee0e4a8729337affc7d930a4da17958f869ef679ee0e4a8729337affc
linuxlinux>= bd03a3e4c9a9df0c6b007045fa7fc8889111a478 < 3bfe04c1273d30b866f4c7c238331ed3b08e58243bfe04c1273d30b866f4c7c238331ed3b08e5824
linuxlinux>= bd03a3e4c9a9df0c6b007045fa7fc8889111a478 < 2caa605079488da9601099fbda460cfc1702839f2caa605079488da9601099fbda460cfc1702839f
linuxlinux>= bd03a3e4c9a9df0c6b007045fa7fc8889111a478 < 6edefe1b6c29a9932f558a898968a9fcbeec57116edefe1b6c29a9932f558a898968a9fcbeec5711
linuxlinux>= bd03a3e4c9a9df0c6b007045fa7fc8889111a478 < 2f03fc340cac9ea1dc63cbf8c93dd2eb0f2278152f03fc340cac9ea1dc63cbf8c93dd2eb0f227815
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 5.4.0-182.2025.4.0-182.202
linuxlinux_kernel>= 0 < 5.15.0-107.1175.15.0-107.117
linuxlinux_kernel>= 0 < 4.4.0-254.2884.4.0-254.288
linuxlinux_kernel>= 0 < 4.15.0-225.2374.15.0-225.237
linuxlinux_kernel>= 3.1 < 5.10.2125.10.212
linuxlinux_kernel>= 5.11 < 5.15.1515.15.151
linuxlinux_kernel>= 5.16 < 6.1.816.1.81
linuxlinux_kernel>= 6.2 < 6.6.216.6.21
linuxlinux_kernel>= 6.7 < 6.7.96.7.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.