cbcvebase.
CVE-2024-26744
published 2024-04-03

CVE-2024-26744: In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Support specifying the srpt_service_guid parameter Make loading ib_srpt with…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Support specifying the srpt_service_guid parameter Make loading ib_srpt with this parameter set work. The current behavior is that setting that parameter while loading the ib_srpt kernel module triggers the following kernel crash: BUG: kernel NULL pointer dereference, address: 0000000000000000 Call Trace: parse_one+0x18c/0x1d0 parse_args+0xe1/0x230 load_module+0x8de/0xa60 init_module_from_file+0x8b/0xd0 idempotent_init_module+0x181/0x240 __x64_sys_finit_module+0x5a/0xb0 do_syscall_64+0x5f/0xe0 entry_SYSCALL_64_after_hwframe+0x6e/0x76

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < 84f1dac960cfa210a3b7a7522e6c2320ae91932b84f1dac960cfa210a3b7a7522e6c2320ae91932b
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < e0055d6461b36bfc25a9d2ab974eef78d36a6738e0055d6461b36bfc25a9d2ab974eef78d36a6738
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < 5a5c039dac1b1b7ba3e91c791f4421052bf79b825a5c039dac1b1b7ba3e91c791f4421052bf79b82
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < 989af2f29342a9a7c7515523d879b698ac8465f4989af2f29342a9a7c7515523d879b698ac8465f4
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < aee4dcfe17219fe60f2821923adea98549060af8aee4dcfe17219fe60f2821923adea98549060af8
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < fe2a73d57319feab4b3b175945671ce43492172ffe2a73d57319feab4b3b175945671ce43492172f
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < c99a827d3cff9f84e1cb997b7cc6386d107aa74dc99a827d3cff9f84e1cb997b7cc6386d107aa74d
linuxlinux>= a42d985bd5b234da8b61347a78dc3057bf7bb94d < fdfa083549de5d50ebf7f6811f33757781e838c0fdfa083549de5d50ebf7f6811f33757781e838c0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 3.3 < 4.19.3084.19.308
linuxlinux_kernel>= 4.20 < 5.10.2115.10.211
linuxlinux_kernel>= 5.11 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16 < 6.1.806.1.80
linuxlinux_kernel>= 6.2 < 6.6.196.6.19
linuxlinux_kernel>= 6.7 < 6.7.76.7.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.