cbcvebase.
CVE-2024-26710
published 2024-04-03

CVE-2024-26710: In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Limit KASAN thread size increase to 32KB KASAN is seen to increase stack…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Limit KASAN thread size increase to 32KB KASAN is seen to increase stack usage, to the point that it was reported to lead to stack overflow on some 32-bit machines (see link). To avoid overflows the stack size was doubled for KASAN builds in commit 3e8635fb2e07 ("powerpc/kasan: Force thread size increase with KASAN"). However with a 32KB stack size to begin with, the doubling leads to a 64KB stack, which causes build errors: arch/powerpc/kernel/switch.S:249: Error: operand out of range (0x000000000000fe50 is not between 0xffffffffffff8000 and 0x0000000000007fff) Although the asm could be reworked, in practice a 32KB stack seems sufficient even for KASAN builds - the additional usage seems to be in the 2-3KB range for a 64-bit KASAN build. So only increase the stack for KASAN if the stack size is < 32KB.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.9-1 (forky)linux 6.8.9-1 (forky)
linuxlinux>= 18f14afe281648e31ed35c9ad2fcb724c4838ad9 < f1acb109505d983779bbb7e20a1ee6244d2b5736f1acb109505d983779bbb7e20a1ee6244d2b5736
linuxlinux>= 58f396513cb1fa4ef91838c78698d458100cc27c < b29b16bd836a838b7690f80e37f8376414c74cbeb29b16bd836a838b7690f80e37f8376414c74cbe
linuxlinux>= 6.1.75 < 6.1.766.1.76
linuxlinux>= 6.6.14 < 6.6.186.6.18
linuxlinux>= 6.7.2 < 6.7.66.7.6
linuxlinux>= 9ccf64e763aca088b0d25c1274af42b1a6a45135 < f9a4c401bf4c5af3437ad221c0a5880a518068d4f9a4c401bf4c5af3437ad221c0a5880a518068d4
linuxlinux>= b38014874530d3776de75679315e8c1fe04aa89b < 4cc31fa07445879a13750cb061bb8c2654975fcb4cc31fa07445879a13750cb061bb8c2654975fcb
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 6.1.75 < 6.1.796.1.79
linuxlinux_kernel>= 6.6.14 < 6.6.186.6.18
linuxlinux_kernel>= 6.7.2 < 6.7.66.7.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.