CVE-2024-26795Out-of-bounds Read in Linux

CWE-125Out-of-bounds Read26 documents7 sources
Severity
5.5MEDIUMNVD
OSV7.0OSV6.5
EPSS
0.0%
top 98.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateJul 26

Description

In the Linux kernel, the following vulnerability has been resolved: riscv: Sparse-Memory/vmemmap out-of-bounds fix Offset vmemmap so that the first page of vmemmap will be mapped to the first page of physical memory in order to ensure that vmemmap’s bounds will be respected during pfn_to_page()/page_to_pfn() operations. The conversion macros will produce correct SV39/48/57 addresses for every possible/valid DRAM_BASE inside the physical memory limits. v2:Address Alex's comments

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel5.45.10.212+5
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.15.0-112.122
CVEListV5linux/linuxd95f1a542c3df396137afa217ef9bd39cb8931ca8af1c121b0102041809bc137ec600d1865eaeedd+6
debiandebian/linux< linux 6.1.82-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

12
OSV
linux-raspi vulnerabilities2024-07-26
OSV
linux-ibm-5.15 vulnerabilities2024-07-10
OSV
linux-hwe-5.15 vulnerabilities2024-07-04
OSV
linux-azure, linux-azure-fde vulnerabilities2024-06-14
OSV
linux-aws, linux-aws-5.15 vulnerabilities2024-06-11

📋Vendor Advisories

12
Ubuntu
Linux kernel vulnerabilities2024-07-26
Ubuntu
Linux kernel (IBM) vulnerabilities2024-07-10
Ubuntu
Linux kernel (HWE) vulnerabilities2024-07-04
Ubuntu
Linux kernel (Azure) vulnerabilities2024-06-14
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-06-11

💬Community

1
Bugzilla
CVE-2024-26795 kernel: riscv: Sparse-Memory/vmemmap out-of-bounds fix2024-04-04