In the Linux kernel, the following vulnerability has been resolved:
kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address
Read from an unsafe address with copy_from_kernel_nofault() in
arch_adjust_kprobe_addr() because this function is used before checking
the address is in text or not. Syzcaller bot found a bug and reported
the case if user specifies inaccessible data area,
arch_adjust_kprobe_addr() will cause a kernel panic.
[ mingo: Clarified the comment. ]
References
Configurations
Configuration 1 (hide)
|
History
18 Sep 2025, 14:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861 - Patch | |
References | () https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b - Patch | |
References | () https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6 - Patch | |
References | () https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483 - Patch | |
References | () https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3 - Patch | |
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
First Time |
Linux
Linux linux Kernel |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CWE | CWE-617 |
21 Nov 2024, 09:03
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861 - | |
References | () https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b - | |
References | () https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6 - | |
References | () https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483 - | |
References | () https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3 - |
01 May 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-01 06:15
Updated : 2025-09-18 14:14
NVD link : CVE-2024-26946
Mitre link : CVE-2024-26946
CVE.ORG link : CVE-2024-26946
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-617
Reachable Assertion