cbcvebase.
CVE-2024-26824
published 2024-04-17

CVE-2024-26824: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - Remove bogus SGL free on zero-length error path When a zero-length…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - Remove bogus SGL free on zero-length error path When a zero-length message is hashed by algif_hash, and an error is triggered, it tries to free an SG list that was never allocated in the first place. Fix this by not freeing the SG list on the zero-length error path.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.7-1 (forky)linux 6.7.7-1 (forky)
linuxlinux
linuxlinux>= b6d972f6898308fbe7e693bf8d44ebfdb1cd2dc4 < 9c82920359b7c1eddaf72069bcfe0ffddf088cd09c82920359b7c1eddaf72069bcfe0ffddf088cd0
linuxlinux>= b6d972f6898308fbe7e693bf8d44ebfdb1cd2dc4 < 775f3c1882a493168e08fdb8cde0865c8f3a8a29775f3c1882a493168e08fdb8cde0865c8f3a8a29
linuxlinux>= b6d972f6898308fbe7e693bf8d44ebfdb1cd2dc4 < 24c890dd712f6345e382256cae8c97abb0406b7024c890dd712f6345e382256cae8c97abb0406b70
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 6.5 < 6.6.186.6.18
linuxlinux_kernel>= 6.7 < 6.7.66.7.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.