CVE-2024-26861 — Race Condition in Linux
Severity
4.7MEDIUMNVD
OSV7.0OSV6.5OSV5.5
EPSS
0.0%
top 98.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 17
Latest updateJul 26
Description
In the Linux kernel, the following vulnerability has been resolved:
wireguard: receive: annotate data-race around receiving_counter.counter
Syzkaller with KCSAN identified a data-race issue when accessing
keypair->receiving_counter.counter. Use READ_ONCE() and WRITE_ONCE()
annotations to mark the data race as intentional.
BUG: KCSAN: data-race in wg_packet_decrypt_worker / wg_packet_rx_poll
write to 0xffff888107765888 of 8 bytes by interrupt on cpu 0:
counter_validate drivers/net/wireguard/r…
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linuxa9e90d9931f3a474f04bab782ccd9d77904941e9 — f87884e0dffd61b47e58bc6e1e2f6843c212b0cc+8
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
17📋Vendor Advisories
17💬Community
1Bugzilla▶
CVE-2024-26861 kernel: wireguard: receive: annotate data-race around receiving_counter.counter↗2024-04-17