cbcvebase.
CVE-2024-26632
published 2024-03-18

CVE-2024-26632: In the Linux kernel, the following vulnerability has been resolved: block: Fix iterating over an empty bio with bio_for_each_folio_all If the bio contains no…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: block: Fix iterating over an empty bio with bio_for_each_folio_all If the bio contains no data, bio_first_folio() calls page_folio() on a NULL pointer and oopses. Move the test that we've reached the end of the bio from bio_next_folio() to bio_first_folio(). [axboe: add unlikely() to error case]

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 640d1930bef4f87ec8d8d2b05f0f6edc1dfcf662 < c6350b5cb78e9024c49eaee6fdb914ad2903a5fec6350b5cb78e9024c49eaee6fdb914ad2903a5fe
linuxlinux>= 640d1930bef4f87ec8d8d2b05f0f6edc1dfcf662 < a6bd8182137a12d22d3f2cee463271bdcb491659a6bd8182137a12d22d3f2cee463271bdcb491659
linuxlinux>= 640d1930bef4f87ec8d8d2b05f0f6edc1dfcf662 < ca3ede3f5893e2d26d4dbdef1eec28a8487fafdeca3ede3f5893e2d26d4dbdef1eec28a8487fafde
linuxlinux>= 640d1930bef4f87ec8d8d2b05f0f6edc1dfcf662 < 7bed6f3d08b7af27b7015da8dc3acf2b9c1f21d77bed6f3d08b7af27b7015da8dc3acf2b9c1f21d7
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 5.17 < 6.1.756.1.75
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.