CVE-2024-26974Time-of-check Time-of-use (TOCTOU) Race Condition in Linux

Severity
7.0HIGHNVD
OSV7.8OSV5.5
EPSS
0.0%
top 89.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateMay 13

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER recovery During the PCI AER system's error recovery process, the kernel driver may encounter a race condition with freeing the reset_data structure's memory. If the device restart will take more than 10 seconds the function scheduling that restart will exit due to a timeout, and the reset_data structure will be freed. However, this data structure is used for completion notificati

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages9 packages

NVDlinux/linux_kernel3.174.19.312+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-189.209+3
CVEListV5linux/linuxd8cba25d2c68992a6e7c1d329b690a9ebe01167ddaba62d9eeddcc5b1081be7d348ca836c83c59d7+9
debiandebian/linux< linux 6.1.85-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

24
OSV
linux-lts-xenial vulnerabilities2025-05-13
OSV
linux-fips vulnerabilities2025-05-12
OSV
linux-aws vulnerabilities2025-05-12
OSV
linux, linux-aws, linux-kvm vulnerabilities2025-05-12
OSV
linux-aws-fips, linux-fips, linux-gcp-fips vulnerabilities2025-05-07

📋Vendor Advisories

25
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2025-05-13
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-05-12
Ubuntu
Linux kernel vulnerabilities2025-05-12
Ubuntu
Linux kernel (AWS) vulnerabilities2025-05-12
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-05-07

💬Community

1
Bugzilla
CVE-2024-26974 kernel: crypto: qat - resolve race condition during AER recovery2024-05-01
CVE-2024-26974 — Linux vulnerability | cvebase