cbcvebase.
CVE-2024-26664
published 2024-04-02

CVE-2024-26664: In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem might be triggered on systems with more than 128 cores per package.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 30cf0dee372baf9b515f2d9c7218f905fddf3cdb < a16afec8e83c56b14a4a73d2e3fb8eec3a8a057ea16afec8e83c56b14a4a73d2e3fb8eec3a8a057e
linuxlinux>= 4.19.264 < 4.19.3074.19.307
linuxlinux>= 4f9dcadc55c21b39b072bb0882362c7edc4340bc < 93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6a93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6a
linuxlinux>= 5.10.152 < 5.10.2105.10.210
linuxlinux>= 5.15.76 < 5.15.1495.15.149
linuxlinux>= 5.4.221 < 5.4.2695.4.269
linuxlinux>= 6.0.6 < 6.16.1
linuxlinux>= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 9bce69419271eb8b2b3ab467387cb59c99d80deb9bce69419271eb8b2b3ab467387cb59c99d80deb
linuxlinux>= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 853a6503c586a71abf27e60a7f8c4fb28092976d853a6503c586a71abf27e60a7f8c4fb28092976d
linuxlinux>= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 3a7753bda55985dc26fae17795cb10d825453ad13a7753bda55985dc26fae17795cb10d825453ad1
linuxlinux>= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 4e440abc894585a34c2904a32cd54af1742311b34e440abc894585a34c2904a32cd54af1742311b3
linuxlinux>= c00cdfc9bd767ee743ad3a4054de17aeb0afcbca < 1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8b1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8b
linuxlinux>= d9f0159da05df869071164edf0c6d7302efc5eca < f0da068c75c20ffc5ba28243ff577531dc2af1fdf0da068c75c20ffc5ba28243ff577531dc2af1fd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 4.19.264 < 4.19.3074.19.307

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.