CVE-2024-26712 — Improper Input Validation in Linux
Severity
4.4MEDIUMNVD
OSV7.8OSV7.0OSV6.5
EPSS
0.0%
top 99.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Latest updateAug 2
Description
In the Linux kernel, the following vulnerability has been resolved:
powerpc/kasan: Fix addr error caused by page alignment
In kasan_init_region, when k_start is not page aligned, at the begin of
for loop, k_cur = k_start & PAGE_MASK is less than k_start, and then
`va = block + k_cur - k_start` is less than block, the addr va is invalid,
because the memory address space from va to block is not alloced by
memblock_alloc, which will not be reserved by memblock_reserve later, it
will be used by ot…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linux663c0c9496a69f80011205ba3194049bcafd681d — 230e89b5ad0a33f530a2a976b3e5e4385cb27882+7
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
14OSV▶
linux-aws-6.5, linux-lowlatency-hwe-6.5, linux-oracle-6.5, linux-starfive-6.5 vulnerabilities↗2024-07-19