CVE-2024-46826 — Improper Input Validation in Linux
Severity
5.5MEDIUMNVD
OSV7.8OSV7.1
EPSS
0.0%
top 99.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 27
Latest updateMay 28
Description
In the Linux kernel, the following vulnerability has been resolved:
ELF: fix kernel.randomize_va_space double read
ELF loader uses "randomize_va_space" twice. It is sysctl and can change
at any moment, so 2 loads could see 2 different values in theory with
unpredictable consequences.
Issue exactly one load for consistent value across one exec.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages6 packages
▶CVEListV5linux/linux32a932332c8bad842804842eaf9651ad6268e637 — 1f81d51141a234ad0a3874b4d185dc27a521cd27+4