CVE-2024-26957 — Use After Free in Linux
Severity
7.8HIGHNVD
OSV7.0OSV5.5
EPSS
0.0%
top 95.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: fix reference counting on zcrypt card objects
Tests with hot-plugging crytpo cards on KVM guests with debug
kernel build revealed an use after free for the load field of
the struct zcrypt_card. The reason was an incorrect reference
handling of the zcrypt card object which could lead to a free
of the zcrypt card object while it was still in use.
This is an example of the slab message:
kernel: 0x00000000885a7512-0…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages5 packages
▶CVEListV5linux/linuxe28d2af43614eb86f59812e7221735fc221bbc10 — 7e500849fa558879a1cde43f80c7c048c2437058+9
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
20📋Vendor Advisories
20💬Community
1Bugzilla
▶