cbcvebase.
CVE-2024-26860
published 2024-04-17

CVE-2024-26860: In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a memory leak when rechecking the data Memory for the "checksums" pointer…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a memory leak when rechecking the data Memory for the "checksums" pointer will leak if the data is rechecked after checksum failure (because the associated kfree won't happen due to 'goto skip_io'). Fix this by freeing the checksums memory before recheck, and just use the "checksum_onstack" memory for storing checksum during recheck.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 6.1.80 < 6.1.836.1.83
linuxlinux>= 6.6.19 < 6.6.236.6.23
linuxlinux>= 6.7.7 < 6.7.116.7.11
linuxlinux>= 906414f4596469004632de29126c55751ed82c5e < 20e21c3c0195d915f33bc7321ee6b362177bf5bf20e21c3c0195d915f33bc7321ee6b362177bf5bf
linuxlinux>= c88f5e553fe38b2ffc4c33d08654e5281b297677 < 6d35654f03c35c273240d85ec67e3f2c3596c4e06d35654f03c35c273240d85ec67e3f2c3596c4e0
linuxlinux>= c88f5e553fe38b2ffc4c33d08654e5281b297677 < 55e565c42dce81a4e49c13262d5bc4eb4c2e588a55e565c42dce81a4e49c13262d5bc4eb4c2e588a
linuxlinux>= d6824a28b244e8a750952848e4bd2167e1e9a17e < 338580a7fb9b0930bb38098007e89cc0fc496bf7338580a7fb9b0930bb38098007e89cc0fc496bf7
linuxlinux>= eb7b14a6a923c5678573c4d238c781cc83fcbc0f < 74abc2fe09691f3d836d8a54d599ca71f1e4287b74abc2fe09691f3d836d8a54d599ca71f1e4287b
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.1.80 < 6.1.836.1.83
linuxlinux_kernel>= 6.6.19 < 6.6.236.6.23
linuxlinux_kernel>= 6.7.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.