cbcvebase.
CVE-2024-26843
published 2024-04-17

CVE-2024-26843: In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been…

PriorityP422medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of pages in a soft-reserved region.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 16993c0f0a43213e23666ea40e9163887f593ac7 < 4fff3d735baea104017f2e3c245e27cdc79f24264fff3d735baea104017f2e3c245e27cdc79f2426
linuxlinux>= 16993c0f0a43213e23666ea40e9163887f593ac7 < 4aa36b62c3eaa869860bf78b1146e9f2b5f782a94aa36b62c3eaa869860bf78b1146e9f2b5f782a9
linuxlinux>= 16993c0f0a43213e23666ea40e9163887f593ac7 < 700c3f642c32721f246e09d3a9511acf40ae42be700c3f642c32721f246e09d3a9511acf40ae42be
linuxlinux>= 16993c0f0a43213e23666ea40e9163887f593ac7 < cf3d6813601fe496de7f023435e31bfffa74ae70cf3d6813601fe496de7f023435e31bfffa74ae70
linuxlinux>= 16993c0f0a43213e23666ea40e9163887f593ac7 < 156cb12ffdcf33883304f0db645e1eadae712fe0156cb12ffdcf33883304f0db645e1eadae712fe0
linuxlinux>= 16993c0f0a43213e23666ea40e9163887f593ac7 < de1034b38a346ef6be25fe8792f5d1e0684d5ff4de1034b38a346ef6be25fe8792f5d1e0684d5ff4
linuxlinux_kernel< 5.10.2115.10.211
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 5.11 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16 < 6.1.806.1.80
linuxlinux_kernel>= 6.2 < 6.6.196.6.19
linuxlinux_kernel>= 6.7 < 6.7.76.7.7

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.