cbcvebase.
CVE-2024-26946
published 2024-05-01

CVE-2024-26946: In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy_from_kernel_nofault() in arch_adjust_kprobe_addr() because this function is used before checking the address is in text or not. Syzcaller bot found a bug and reported the case if user specifies inaccessible data area, arch_adjust_kprobe_addr() will cause a kernel panic. [ mingo: Clarified the comment. ]

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= cc66bb91457827f62e2b6cb2518666820f0a6c48 < 6417684315087904fffe8966d27ca74398c57dd66417684315087904fffe8966d27ca74398c57dd6
linuxlinux>= cc66bb91457827f62e2b6cb2518666820f0a6c48 < f13edd1871d4fb4ab829aff629d47914e251bae3f13edd1871d4fb4ab829aff629d47914e251bae3
linuxlinux>= cc66bb91457827f62e2b6cb2518666820f0a6c48 < 20fdb21eabaeb8f78f8f701f56d14ea0836ec86120fdb21eabaeb8f78f8f701f56d14ea0836ec861
linuxlinux>= cc66bb91457827f62e2b6cb2518666820f0a6c48 < b69f577308f1070004cafac106dd1a44099e5483b69f577308f1070004cafac106dd1a44099e5483
linuxlinux>= cc66bb91457827f62e2b6cb2518666820f0a6c48 < 4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.18 < 6.1.846.1.84
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.