cbcvebase.
CVE-2024-26957
published 2024-05-01

CVE-2024-26957: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: fix reference counting on zcrypt card objects Tests with hot-plugging crytpo…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: fix reference counting on zcrypt card objects Tests with hot-plugging crytpo cards on KVM guests with debug kernel build revealed an use after free for the load field of the struct zcrypt_card. The reason was an incorrect reference handling of the zcrypt card object which could lead to a free of the zcrypt card object while it was still in use. This is an example of the slab message: kernel: 0x00000000885a7512-0x00000000885a7513 @offset=1298. First byte 0x68 instead of 0x6b kernel: Allocated in zcrypt_card_alloc+0x36/0x70 [zcrypt] age=18046 cpu=3 pid=43 kernel: kmalloc_trace+0x3f2/0x470 kernel: zcrypt_card_alloc+0x36/0x70 [zcrypt] kernel: zcrypt_cex4_card_probe+0x26/0x380 [zcrypt_cex4] kernel: ap_device_probe+0x15c/0x290 kernel: really_probe+0xd2/0x468 kernel: driver_probe_device+0x40/0xf0 kernel: __device_attach_driver+0xc0/0x140 kernel: bus_for_each_drv+0x8c/0xd0 kernel: __device_attach+0x114/0x198 kernel: bus_probe_device+0xb4/0xc8 kernel: device_add+0x4d2/0x6e0 kernel: ap_scan_adapter+0x3d0/0x7c0 kernel: ap_scan_bus+0x5a/0x3b0 kernel: ap_scan_bus_wq_callback+0x40/0x60 kernel: process_one_work+0x26e/0x620 kernel: worker_thread+0x21c/0x440 kernel: Freed in zcrypt_card_put+0x54/0x80 [zcrypt] age=9024 cpu=3 pid=43 kernel: kfree+0x37e/0x418 kernel: zcrypt_card_put+0x54/0x80 [zcrypt] kernel: ap_device_remove+0x4c/0xe0 kernel: device_release_driver_internal+0x1c4/0x270 kernel: bus_remove_device+0x100/0x188 kernel: device_del+0x164/0x3c0 kernel: device_unregister+0x30/0x90 kernel: ap_scan_adapter+0xc8/0x7c0 kernel: ap_scan_bus+0x5a/0x3b0 kernel: ap_scan_bus_wq_callback+0x40/0x60 kernel: process_one_work+0x26e/0x620 kernel: worker_thread+0x21c/0x440 kernel: kthread+0x150/0x168 kernel: __ret_from_fork+0x3c/0x58 kernel: ret_from_fork+0xa/0x30 kernel: Slab 0x00000372022169c0 objects=20 used=18 fp=0x00000000885a7c88 flags=0x3ffff00000000a00(workingset|slab|node=0|zone=1|lastcpupid=0x1ffff) k

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < 7e500849fa558879a1cde43f80c7c048c24370587e500849fa558879a1cde43f80c7c048c2437058
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < 9daddee03de3f231012014dab8ab2b277a116a559daddee03de3f231012014dab8ab2b277a116a55
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < 6470078ab3d8f222115e11c4ec67351f3031b3dd6470078ab3d8f222115e11c4ec67351f3031b3dd
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < a55677878b93e9ebc31f66d0e2fb93be5e7836a6a55677878b93e9ebc31f66d0e2fb93be5e7836a6
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < b7f6c3630eb3f103115ab0d7613588064f665d0db7f6c3630eb3f103115ab0d7613588064f665d0d
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < a64ab862e84e3e698cd351a87cdb504c7fc575caa64ab862e84e3e698cd351a87cdb504c7fc575ca
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < befb7f889594d23e1b475720cf93efd2f77df000befb7f889594d23e1b475720cf93efd2f77df000
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < 394b6d8bbdf9ddee6d5bcf3e1f3e9f23eecd6484394b6d8bbdf9ddee6d5bcf3e1f3e9f23eecd6484
linuxlinux>= e28d2af43614eb86f59812e7221735fc221bbc10 < 50ed48c80fecbe17218afed4f8bed005c802976c50ed48c80fecbe17218afed4f8bed005c802976c
linuxlinux_kernel< 4.19.3124.19.312
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.246.6.24

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.