cbcvebase.
CVE-2024-26712
published 2024-04-03

CVE-2024-26712: In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix addr error caused by page alignment In kasan_init_region, when k_start…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix addr error caused by page alignment In kasan_init_region, when k_start is not page aligned, at the begin of for loop, k_cur = k_start & PAGE_MASK is less than k_start, and then `va = block + k_cur - k_start` is less than block, the addr va is invalid, because the memory address space from va to block is not alloced by memblock_alloc, which will not be reserved by memblock_reserve later, it will be used by other places. As a result, memory overwriting occurs. for example: int __init __weak kasan_init_region(void *start, size_t size) { [...] /* if say block(dcd97000) k_start(feef7400) k_end(feeff3fe) */ block = memblock_alloc(k_end - k_start, PAGE_SIZE); [...] for (k_cur = k_start & PAGE_MASK; k_cur < k_end; k_cur += PAGE_SIZE) { /* at the begin of for loop * block(dcd97000) va(dcd96c00) k_cur(feef7000) k_start(feef7400) * va(dcd96c00) is less than block(dcd97000), va is invalid */ void *va = block + k_cur - k_start; [...] } [...] } Therefore, page alignment is performed on k_start before memblock_alloc() to ensure the validity of the VA address.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.3.6 < 5.45.4
linuxlinux>= 663c0c9496a69f80011205ba3194049bcafd681d < 230e89b5ad0a33f530a2a976b3e5e4385cb27882230e89b5ad0a33f530a2a976b3e5e4385cb27882
linuxlinux>= 663c0c9496a69f80011205ba3194049bcafd681d < 2738e0aa2fb24a7ab9c878d912dc2b239738c6c62738e0aa2fb24a7ab9c878d912dc2b239738c6c6
linuxlinux>= 663c0c9496a69f80011205ba3194049bcafd681d < 0c09912dd8387e228afcc5e34ac5d79b1e3a10580c09912dd8387e228afcc5e34ac5d79b1e3a1058
linuxlinux>= 663c0c9496a69f80011205ba3194049bcafd681d < 0516c06b19dc64807c10e01bb99b552bdf2d7dbe0516c06b19dc64807c10e01bb99b552bdf2d7dbe
linuxlinux>= 663c0c9496a69f80011205ba3194049bcafd681d < 70ef2ba1f4286b2b73675aeb424b590c92d57b2570ef2ba1f4286b2b73675aeb424b590c92d57b25
linuxlinux>= 663c0c9496a69f80011205ba3194049bcafd681d < 4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b04a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.796.1.79
linuxlinux_kernel>= 5.4 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.186.6.18

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.