cbcvebase.
CVE-2024-26795
published 2024-04-04

CVE-2024-26795: In the Linux kernel, the following vulnerability has been resolved: riscv: Sparse-Memory/vmemmap out-of-bounds fix Offset vmemmap so that the first page of…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: Sparse-Memory/vmemmap out-of-bounds fix Offset vmemmap so that the first page of vmemmap will be mapped to the first page of physical memory in order to ensure that vmemmap’s bounds will be respected during pfn_to_page()/page_to_pfn() operations. The conversion macros will produce correct SV39/48/57 addresses for every possible/valid DRAM_BASE inside the physical memory limits. v2:Address Alex's comments

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= d95f1a542c3df396137afa217ef9bd39cb8931ca < 5941a90c55d3bfba732b32208d58d997600b44ef5941a90c55d3bfba732b32208d58d997600b44ef
linuxlinux>= d95f1a542c3df396137afa217ef9bd39cb8931ca < 8310080799b40fd9f2a8b808c657269678c149af8310080799b40fd9f2a8b808c657269678c149af
linuxlinux>= d95f1a542c3df396137afa217ef9bd39cb8931ca < a278d5c60f21aa15d540abb2f2da6e6d795c3e6ea278d5c60f21aa15d540abb2f2da6e6d795c3e6e
linuxlinux>= d95f1a542c3df396137afa217ef9bd39cb8931ca < 2a1728c15ec4f45ed9248ae22f626541c179bfbe2a1728c15ec4f45ed9248ae22f626541c179bfbe
linuxlinux>= d95f1a542c3df396137afa217ef9bd39cb8931ca < a11dd49dcb9376776193e15641f84fcc1e5980c9a11dd49dcb9376776193e15641f84fcc1e5980c9
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 5.11 < 5.15.1515.15.151
linuxlinux_kernel>= 5.16 < 6.1.816.1.81
linuxlinux_kernel>= 5.4 < 5.10.2125.10.212
linuxlinux_kernel>= 6.2 < 6.6.216.6.21
linuxlinux_kernel>= 6.7 < 6.7.96.7.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.