CVE-2024-26926 — Improper Validation of Specified Index, Position, or Offset in Input in Linux
CWE-1285 — Improper Validation of Specified Index, Position, or Offset in Input52 documents8 sources
Severity
5.5MEDIUMNVD
OSV7.0OSV6.8
EPSS
0.2%
top 63.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
binder: check offset alignment in binder_get_object()
Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying
txn") introduced changes to how binder objects are copied. In doing so,
it unintentionally removed an offset alignment check done through calls
to binder_alloc_copy_from_buffer() -> check_buffer().
These calls were replaced in binder_get_object() with copy_from_user(),
so now an explicit offset alignme…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages6 packages
▶CVEListV5linux/linuxc056a6ba35e00ae943e377eb09abd77a6915b31a — 68a28f551e4690db2b27b3db716c7395f6fada12+8
Also affects: Debian Linux 10.0