cbcvebase.
CVE-2024-26764
published 2024-04-03

CVE-2024-26764: In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio If kiocb_set_cancel_fn()…

PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio If kiocb_set_cancel_fn() is called for I/O submitted via io_uring, the following kernel warning appears: WARNING: CPU: 3 PID: 368 at fs/aio.c:598 kiocb_set_cancel_fn+0x9c/0xa8 Call trace: kiocb_set_cancel_fn+0x9c/0xa8 ffs_epfile_read_iter+0x144/0x1d0 io_read+0x19c/0x498 io_issue_sqe+0x118/0x27c io_submit_sqes+0x25c/0x5fc __arm64_sys_io_uring_enter+0x104/0xab0 invoke_syscall+0x58/0x11c el0_svc_common+0xb4/0xf4 do_el0_svc+0x2c/0xb0 el0_svc+0x2c/0xa4 el0t_64_sync_handler+0x68/0xb4 el0t_64_sync+0x1a4/0x1a8 Fix this by setting the IOCB_AIO_RW flag for read and write I/O that is submitted by libaio.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < 337b543e274fe7a8f47df3c8293cc6686ffa620f337b543e274fe7a8f47df3c8293cc6686ffa620f
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < ea1cd64d59f22d6d13f367d62ec6e27b9344695fea1cd64d59f22d6d13f367d62ec6e27b9344695f
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < d7b6fa97ec894edd02f64b83e5e72e1aa352f353d7b6fa97ec894edd02f64b83e5e72e1aa352f353
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < 18f614369def2a11a52f569fe0f910b199d1348718f614369def2a11a52f569fe0f910b199d13487
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < e7e23fc5d5fe422827c9a43ecb579448f73876c7e7e23fc5d5fe422827c9a43ecb579448f73876c7
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < 1dc7d74fe456944a9b1c57bd776280249f441ac61dc7d74fe456944a9b1c57bd776280249f441ac6
linuxlinux>= 04b2fa9f8f36ec6fb6fd1c9dc9df6fff0cd27323 < b820de741ae48ccf50dd95e297889c286ff4f760b820de741ae48ccf50dd95e297889c286ff4f760
linuxlinux_kernel< 4.19.3084.19.308
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.20 < 5.4.2705.4.270
linuxlinux_kernel>= 5.11 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16 < 6.1.806.1.80
linuxlinux_kernel>= 5.5 < 5.10.2115.10.211
linuxlinux_kernel>= 6.2 < 6.6.196.6.19
linuxlinux_kernel>= 6.7 < 6.7.76.7.7

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.