CVE-2024-26946

In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy_from_kernel_nofault() in arch_adjust_kprobe_addr() because this function is used before checking the address is in text or not. Syzcaller bot found a bug and reported the case if user specifies inaccessible data area, arch_adjust_kprobe_addr() will cause a kernel panic. [ mingo: Clarified the comment. ]
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

18 Sep 2025, 14:14

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861 - () https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861 - Patch
References () https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b - () https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b - Patch
References () https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6 - () https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6 - Patch
References () https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483 - () https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483 - Patch
References () https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3 - () https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-617

21 Nov 2024, 09:03

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: kprobes/x86: use copy_from_kernel_nofault() para leer desde una dirección no segura Lea desde una dirección no segura con copy_from_kernel_nofault() en arch_adjust_kprobe_addr() porque esta función se usa antes de verificar que la dirección esté en texto O no. El bot Syzcaller encontró un error e informó el caso si el usuario especifica un área de datos inaccesible, arch_adjust_kprobe_addr() provocará un pánico en el kernel. [ mingo: Aclaró el comentario. ]
References () https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861 - () https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861 -
References () https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b - () https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b -
References () https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6 - () https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6 -
References () https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483 - () https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483 -
References () https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3 - () https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3 -

01 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 06:15

Updated : 2025-09-18 14:14


NVD link : CVE-2024-26946

Mitre link : CVE-2024-26946

CVE.ORG link : CVE-2024-26946


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-617

Reachable Assertion