cbcvebase.
CVE-2024-26988
published 2024-05-01

CVE-2024-26988: In the Linux kernel, the following vulnerability has been resolved: init/main.c: Fix potential static_command_line memory overflow We allocate memory of size…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: init/main.c: Fix potential static_command_line memory overflow We allocate memory of size 'xlen + strlen(boot_command_line) + 1' for static_command_line, but the strings copied into static_command_line are extra_command_line and command_line, rather than extra_command_line and boot_command_line. When strlen(command_line) > strlen(boot_command_line), static_command_line will overflow. This patch just recovers strlen(command_line) which was miss-consolidated with strlen(boot_command_line) in the commit f5c7310ac73e ("init/main: add checks for the return value of memblock_alloc*()")

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxlinux
linuxlinux>= f5c7310ac73ea270e3a1acdb73d1b4817f11fd67 < 2ef607ea103616aec0289f1b65d103d499fa903a2ef607ea103616aec0289f1b65d103d499fa903a
linuxlinux>= f5c7310ac73ea270e3a1acdb73d1b4817f11fd67 < 0dc727a4e05400205358a22c3d01ccad2c8e1fe40dc727a4e05400205358a22c3d01ccad2c8e1fe4
linuxlinux>= f5c7310ac73ea270e3a1acdb73d1b4817f11fd67 < 76c2f4d426a5358fced5d5990744d46f10a4ccea76c2f4d426a5358fced5d5990744d46f10a4ccea
linuxlinux>= f5c7310ac73ea270e3a1acdb73d1b4817f11fd67 < 81cf85ae4f2dd5fa3e43021782aa72c4c85558e881cf85ae4f2dd5fa3e43021782aa72c4c85558e8
linuxlinux>= f5c7310ac73ea270e3a1acdb73d1b4817f11fd67 < 936a02b5a9630c5beb0353c3085cc49d86c57034936a02b5a9630c5beb0353c3085cc49d86c57034
linuxlinux>= f5c7310ac73ea270e3a1acdb73d1b4817f11fd67 < 46dad3c1e57897ab9228332f03e1c14798d2d3b946dad3c1e57897ab9228332f03e1c14798d2d3b9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 5.1 < 5.10.2165.10.216
linuxlinux_kernel>= 5.11 < 5.15.1575.15.157
linuxlinux_kernel>= 5.16 < 6.1.886.1.88
linuxlinux_kernel>= 6.2 < 6.6.296.6.29
linuxlinux_kernel>= 6.7 < 6.8.86.8.8
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8MEDIUM
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.