CVE-2024-26592 (GCVE-0-2024-26592)
Vulnerability from cvelistv5
Published
2024-02-22 16:21
Modified
2026-08-05 11:26
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_transport` in ksmbd_tcp_new_connection() function.
Impacted products
Vendor Product Version
Linux Linux Version: a848c4f15ab6d5d405dbee7de5da71839b2bf35e
Version: a848c4f15ab6d5d405dbee7de5da71839b2bf35e
Version: a848c4f15ab6d5d405dbee7de5da71839b2bf35e
Version: a848c4f15ab6d5d405dbee7de5da71839b2bf35e
Version: a848c4f15ab6d5d405dbee7de5da71839b2bf35e
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:07:19.957Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/999daf367b924fdf14e9d83e034ee0f86bc17ec6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/380965e48e9c32ee4263c023e1d830ea7e462ed1"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/24290ba94cd0136e417283b0dbf8fcdabcf62111"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/69d54650b751532d1e1613a4fb433e591aeef126"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/38d20c62903d669693a1869aa68c4dd5674e2544"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "affected",
            "product": "linux_kernel",
            "vendor": "linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.15"
              },
              {
                "lessThan": "999daf367b92",
                "status": "affected",
                "version": "a848c4f15ab6",
                "versionType": "git"
              },
              {
                "lessThan": "380965e48e9c",
                "status": "affected",
                "version": "a848c4f15ab6",
                "versionType": "git"
              },
              {
                "lessThan": "24290ba94cd0",
                "status": "affected",
                "version": "a848c4f15ab6",
                "versionType": "git"
              },
              {
                "lessThan": "69d54650b751",
                "status": "affected",
                "version": "a848c4f15ab6",
                "versionType": "git"
              },
              {
                "lessThan": "38d20c62903d",
                "status": "affected",
                "version": "a848c4f15ab6",
                "versionType": "git"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-26592",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-02-27T05:00:16.236632Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-416",
                "description": "CWE-416 Use After Free",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-08-27T15:00:34.971Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/server/connection.c",
            "fs/smb/server/connection.h",
            "fs/smb/server/transport_rdma.c",
            "fs/smb/server/transport_tcp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "999daf367b924fdf14e9d83e034ee0f86bc17ec6",
              "status": "affected",
              "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
              "versionType": "git"
            },
            {
              "lessThan": "380965e48e9c32ee4263c023e1d830ea7e462ed1",
              "status": "affected",
              "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
              "versionType": "git"
            },
            {
              "lessThan": "24290ba94cd0136e417283b0dbf8fcdabcf62111",
              "status": "affected",
              "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
              "versionType": "git"
            },
            {
              "lessThan": "69d54650b751532d1e1613a4fb433e591aeef126",
              "status": "affected",
              "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
              "versionType": "git"
            },
            {
              "lessThan": "38d20c62903d669693a1869aa68c4dd5674e2544",
              "status": "affected",
              "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/server/connection.c",
            "fs/smb/server/connection.h",
            "fs/smb/server/transport_rdma.c",
            "fs/smb/server/transport_tcp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "lessThan": "5.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.149",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.75",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.149",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.75",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.14",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.2",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix UAF issue in ksmbd_tcp_new_connection()\n\nThe race is between the handling of a new TCP connection and\nits disconnection. It leads to UAF on `struct tcp_transport` in\nksmbd_tcp_new_connection() function."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - ksmbd is the in-kernel SMB server listening on TCP port 445; the vulnerable code is `ksmbd_tcp_new_connection()`, invoked directly from `kernel_accept()` on a remote peer\u0027s TCP connection. No local access to the target is required.\nAC:L - The attacker controls both sides of the race \u2014 connecting spawns the handler kthread, and immediately closing (FIN, or RST via SO_LINGER{1,0}) drives that kthread down the shortest possible path to `free_transport()`/`kfree(t)` while the acceptor still has to perform its stale store. Attempts are unauthenticated, cost one TCP handshake each, and can be repeated thousands of times per second while flooding the single acceptor kthread to force preemption.\nPR:N - The path runs at TCP accept time, before SMB2 NEGOTIATE and SESSION_SETUP and before any NTLMSSP/Kerberos credential is processed; no share, account, or guest access is needed. Merely completing a TCP handshake to port 445 reaches the vulnerable code.\nUI:N - Exploitation requires only that the attacker connect to and disconnect from the ksmbd port; no action by any local user or administrator is involved.\nS:U - The corrupted memory and the resulting code execution are within the kernel\u0027s own security authority \u2014 a standard in-kernel use-after-free with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The freed `struct tcp_transport` lives in the general kmalloc-64 cache, and the attacker can reclaim the slot with sprayed objects (including via parallel connections) before the stale write and readback occur; corrupting a pointer field of a reclaimed victim object yields a read primitive over kernel memory, disclosing credentials, keys, and SMB share data.\nI:H - The bug is a use-after-free *write* \u2014 a live `task_struct *` is stored at a fixed offset 16 into a freed general-purpose slab object, overwriting whatever object reclaims that slot. Corrupting a pointer/list field of a sprayed victim object is a classic route to an arbitrary write and control-flow hijack in ring 0.\nA:H - Even without successful heap grooming, the stale write and subsequent `IS_ERR()` read on freed slab memory corrupt unrelated kernel objects, producing oopses and panics (KASAN reports a slab-use-after-free write). An unauthenticated attacker can retry the connect/disconnect race indefinitely until the machine crashes."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:26:07.571Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/999daf367b924fdf14e9d83e034ee0f86bc17ec6"
        },
        {
          "url": "https://git.kernel.org/stable/c/380965e48e9c32ee4263c023e1d830ea7e462ed1"
        },
        {
          "url": "https://git.kernel.org/stable/c/24290ba94cd0136e417283b0dbf8fcdabcf62111"
        },
        {
          "url": "https://git.kernel.org/stable/c/69d54650b751532d1e1613a4fb433e591aeef126"
        },
        {
          "url": "https://git.kernel.org/stable/c/38d20c62903d669693a1869aa68c4dd5674e2544"
        }
      ],
      "title": "ksmbd: fix UAF issue in ksmbd_tcp_new_connection()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26592",
    "datePublished": "2024-02-22T16:21:44.626Z",
    "dateReserved": "2024-02-19T14:20:24.126Z",
    "dateUpdated": "2026-08-05T11:26:07.571Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/999daf367b924fdf14e9d83e034ee0f86bc17ec6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/380965e48e9c32ee4263c023e1d830ea7e462ed1\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/24290ba94cd0136e417283b0dbf8fcdabcf62111\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/69d54650b751532d1e1613a4fb433e591aeef126\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/38d20c62903d669693a1869aa68c4dd5674e2544\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:07:19.957Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26592\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-02-27T05:00:16.236632Z\"}}}], \"affected\": [{\"cpes\": [\"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\"], \"vendor\": \"linux\", \"product\": \"linux_kernel\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.15\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6\", \"lessThan\": \"999daf367b92\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6\", \"lessThan\": \"380965e48e9c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6\", \"lessThan\": \"24290ba94cd0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6\", \"lessThan\": \"69d54650b751\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6\", \"lessThan\": \"38d20c62903d\", \"versionType\": \"git\"}], \"defaultStatus\": \"affected\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-416\", \"description\": \"CWE-416 Use After Free\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-08-27T15:00:02.105Z\"}}], \"cna\": {\"title\": \"ksmbd: fix UAF issue in ksmbd_tcp_new_connection()\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 9.8, \"baseSeverity\": \"CRITICAL\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - ksmbd is the in-kernel SMB server listening on TCP port 445; the vulnerable code is `ksmbd_tcp_new_connection()`, invoked directly from `kernel_accept()` on a remote peer\u0027s TCP connection. No local access to the target is required.\\nAC:L - The attacker controls both sides of the race \\u2014 connecting spawns the handler kthread, and immediately closing (FIN, or RST via SO_LINGER{1,0}) drives that kthread down the shortest possible path to `free_transport()`/`kfree(t)` while the acceptor still has to perform its stale store. Attempts are unauthenticated, cost one TCP handshake each, and can be repeated thousands of times per second while flooding the single acceptor kthread to force preemption.\\nPR:N - The path runs at TCP accept time, before SMB2 NEGOTIATE and SESSION_SETUP and before any NTLMSSP/Kerberos credential is processed; no share, account, or guest access is needed. Merely completing a TCP handshake to port 445 reaches the vulnerable code.\\nUI:N - Exploitation requires only that the attacker connect to and disconnect from the ksmbd port; no action by any local user or administrator is involved.\\nS:U - The corrupted memory and the resulting code execution are within the kernel\u0027s own security authority \\u2014 a standard in-kernel use-after-free with no crossing of a VM, IOMMU, or sandbox boundary.\\nC:H - The freed `struct tcp_transport` lives in the general kmalloc-64 cache, and the attacker can reclaim the slot with sprayed objects (including via parallel connections) before the stale write and readback occur; corrupting a pointer field of a reclaimed victim object yields a read primitive over kernel memory, disclosing credentials, keys, and SMB share data.\\nI:H - The bug is a use-after-free *write* \\u2014 a live `task_struct *` is stored at a fixed offset 16 into a freed general-purpose slab object, overwriting whatever object reclaims that slot. Corrupting a pointer/list field of a sprayed victim object is a classic route to an arbitrary write and control-flow hijack in ring 0.\\nA:H - Even without successful heap grooming, the stale write and subsequent `IS_ERR()` read on freed slab memory corrupt unrelated kernel objects, producing oopses and panics (KASAN reports a slab-use-after-free write). An unauthenticated attacker can retry the connect/disconnect race indefinitely until the machine crashes.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"a848c4f15ab6d5d405dbee7de5da71839b2bf35e\", \"lessThan\": \"999daf367b924fdf14e9d83e034ee0f86bc17ec6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6d5d405dbee7de5da71839b2bf35e\", \"lessThan\": \"380965e48e9c32ee4263c023e1d830ea7e462ed1\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6d5d405dbee7de5da71839b2bf35e\", \"lessThan\": \"24290ba94cd0136e417283b0dbf8fcdabcf62111\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6d5d405dbee7de5da71839b2bf35e\", \"lessThan\": \"69d54650b751532d1e1613a4fb433e591aeef126\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a848c4f15ab6d5d405dbee7de5da71839b2bf35e\", \"lessThan\": \"38d20c62903d669693a1869aa68c4dd5674e2544\", \"versionType\": \"git\"}], \"programFiles\": [\"fs/smb/server/connection.c\", \"fs/smb/server/connection.h\", \"fs/smb/server/transport_rdma.c\", \"fs/smb/server/transport_tcp.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.15\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.15\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.149\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.75\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.14\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/smb/server/connection.c\", \"fs/smb/server/connection.h\", \"fs/smb/server/transport_rdma.c\", \"fs/smb/server/transport_tcp.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/999daf367b924fdf14e9d83e034ee0f86bc17ec6\"}, {\"url\": \"https://git.kernel.org/stable/c/380965e48e9c32ee4263c023e1d830ea7e462ed1\"}, {\"url\": \"https://git.kernel.org/stable/c/24290ba94cd0136e417283b0dbf8fcdabcf62111\"}, {\"url\": \"https://git.kernel.org/stable/c/69d54650b751532d1e1613a4fb433e591aeef126\"}, {\"url\": \"https://git.kernel.org/stable/c/38d20c62903d669693a1869aa68c4dd5674e2544\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nksmbd: fix UAF issue in ksmbd_tcp_new_connection()\\n\\nThe race is between the handling of a new TCP connection and\\nits disconnection. It leads to UAF on `struct tcp_transport` in\\nksmbd_tcp_new_connection() function.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.149\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.75\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.14\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.2\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"5.15\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:26:07.571Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26592\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:26:07.571Z\", \"dateReserved\": \"2024-02-19T14:20:24.126Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-02-22T16:21:44.626Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…