CVE-2024-26712 (GCVE-0-2024-26712)
Vulnerability from cvelistv5
Published
2024-04-03 14:55
Modified
2026-08-05 11:26
Summary
In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix addr error caused by page alignment In kasan_init_region, when k_start is not page aligned, at the begin of for loop, k_cur = k_start & PAGE_MASK is less than k_start, and then `va = block + k_cur - k_start` is less than block, the addr va is invalid, because the memory address space from va to block is not alloced by memblock_alloc, which will not be reserved by memblock_reserve later, it will be used by other places. As a result, memory overwriting occurs. for example: int __init __weak kasan_init_region(void *start, size_t size) { [...] /* if say block(dcd97000) k_start(feef7400) k_end(feeff3fe) */ block = memblock_alloc(k_end - k_start, PAGE_SIZE); [...] for (k_cur = k_start & PAGE_MASK; k_cur < k_end; k_cur += PAGE_SIZE) { /* at the begin of for loop * block(dcd97000) va(dcd96c00) k_cur(feef7000) k_start(feef7400) * va(dcd96c00) is less than block(dcd97000), va is invalid */ void *va = block + k_cur - k_start; [...] } [...] } Therefore, page alignment is performed on k_start before memblock_alloc() to ensure the validity of the VA address.
Impacted products
Vendor Product Version
Linux Linux Version: 663c0c9496a69f80011205ba3194049bcafd681d
Version: 663c0c9496a69f80011205ba3194049bcafd681d
Version: 663c0c9496a69f80011205ba3194049bcafd681d
Version: 663c0c9496a69f80011205ba3194049bcafd681d
Version: 663c0c9496a69f80011205ba3194049bcafd681d
Version: 663c0c9496a69f80011205ba3194049bcafd681d
Version: 5ce93076d8ee2a0fac3ad4adbd2e91b6197146db
Version: 5.3.6   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 4.4,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "HIGH",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-26712",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-04-04T15:22:01.316380Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-05-07T20:00:37.857Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:14:12.618Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/230e89b5ad0a33f530a2a976b3e5e4385cb27882"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2738e0aa2fb24a7ab9c878d912dc2b239738c6c6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/0c09912dd8387e228afcc5e34ac5d79b1e3a1058"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/0516c06b19dc64807c10e01bb99b552bdf2d7dbe"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/70ef2ba1f4286b2b73675aeb424b590c92d57b25"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/powerpc/mm/kasan/init_32.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "230e89b5ad0a33f530a2a976b3e5e4385cb27882",
              "status": "affected",
              "version": "663c0c9496a69f80011205ba3194049bcafd681d",
              "versionType": "git"
            },
            {
              "lessThan": "2738e0aa2fb24a7ab9c878d912dc2b239738c6c6",
              "status": "affected",
              "version": "663c0c9496a69f80011205ba3194049bcafd681d",
              "versionType": "git"
            },
            {
              "lessThan": "0c09912dd8387e228afcc5e34ac5d79b1e3a1058",
              "status": "affected",
              "version": "663c0c9496a69f80011205ba3194049bcafd681d",
              "versionType": "git"
            },
            {
              "lessThan": "0516c06b19dc64807c10e01bb99b552bdf2d7dbe",
              "status": "affected",
              "version": "663c0c9496a69f80011205ba3194049bcafd681d",
              "versionType": "git"
            },
            {
              "lessThan": "70ef2ba1f4286b2b73675aeb424b590c92d57b25",
              "status": "affected",
              "version": "663c0c9496a69f80011205ba3194049bcafd681d",
              "versionType": "git"
            },
            {
              "lessThan": "4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0",
              "status": "affected",
              "version": "663c0c9496a69f80011205ba3194049bcafd681d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ce93076d8ee2a0fac3ad4adbd2e91b6197146db",
              "versionType": "git"
            },
            {
              "lessThan": "5.4",
              "status": "affected",
              "version": "5.3.6",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/powerpc/mm/kasan/init_32.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.4"
            },
            {
              "lessThan": "5.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.149",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.79",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.18",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.210",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.149",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.79",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.18",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.6",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.3.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/kasan: Fix addr error caused by page alignment\n\nIn kasan_init_region, when k_start is not page aligned, at the begin of\nfor loop, k_cur = k_start \u0026 PAGE_MASK is less than k_start, and then\n`va = block + k_cur - k_start` is less than block, the addr va is invalid,\nbecause the memory address space from va to block is not alloced by\nmemblock_alloc, which will not be reserved by memblock_reserve later, it\nwill be used by other places.\n\nAs a result, memory overwriting occurs.\n\nfor example:\nint __init __weak kasan_init_region(void *start, size_t size)\n{\n[...]\n\t/* if say block(dcd97000) k_start(feef7400) k_end(feeff3fe) */\n\tblock = memblock_alloc(k_end - k_start, PAGE_SIZE);\n\t[...]\n\tfor (k_cur = k_start \u0026 PAGE_MASK; k_cur \u003c k_end; k_cur += PAGE_SIZE) {\n\t\t/* at the begin of for loop\n\t\t * block(dcd97000) va(dcd96c00) k_cur(feef7000) k_start(feef7400)\n\t\t * va(dcd96c00) is less than block(dcd97000), va is invalid\n\t\t */\n\t\tvoid *va = block + k_cur - k_start;\n\t\t[...]\n\t}\n[...]\n}\n\nTherefore, page alignment is performed on k_start before\nmemblock_alloc() to ensure the validity of the VA address."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is `__init`/boot-time PPC32 KASAN shadow setup with no network-facing entry point; the resulting aliased page is exercised only by local kernel activity (allocations, module loads) on the affected machine.\nAC:L - On a system that boots into the misaligned state, the corrupting writes are continuous and trivially driven \u2014 any ordinary allocation/free path writes KASAN shadow bytes into the co-owned page, requiring no special timing, race, or memory layout the attacker must win.\nPR:L - No elevated privilege is needed to drive the corruption; an unprivileged local process performing ordinary syscalls generates the kmalloc/kfree shadow poisoning that writes into the unreserved page, and running a KASAN kernel is a configuration precondition rather than a privilege the attacker exercises.\nUI:N - The bad shadow mapping is established autonomously during boot and the corruption proceeds without any victim action.\nS:U - Kernel memory corrupting other kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The unreserved page is aliased into the KASAN shadow window while simultaneously being allocated to arbitrary consumers (page cache, slab, user pages), so contents of other security contexts are exposed through the shadow mapping and the uncontrolled corruption is leverageable for disclosure.\nI:H - This is out-of-bounds kernel writes into a page owned by unrelated code \u2014 the commit explicitly states \"memory overwriting occurs\" \u2014 corrupting live slab objects, page tables, or page cache, which is memory corruption exploitable for control-flow influence.\nA:H - Silent overwriting of randomly allocated pages, including potential page tables and slab metadata, reliably produces oopses and kernel panics."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:26:49.646Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/230e89b5ad0a33f530a2a976b3e5e4385cb27882"
        },
        {
          "url": "https://git.kernel.org/stable/c/2738e0aa2fb24a7ab9c878d912dc2b239738c6c6"
        },
        {
          "url": "https://git.kernel.org/stable/c/0c09912dd8387e228afcc5e34ac5d79b1e3a1058"
        },
        {
          "url": "https://git.kernel.org/stable/c/0516c06b19dc64807c10e01bb99b552bdf2d7dbe"
        },
        {
          "url": "https://git.kernel.org/stable/c/70ef2ba1f4286b2b73675aeb424b590c92d57b25"
        },
        {
          "url": "https://git.kernel.org/stable/c/4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0"
        }
      ],
      "title": "powerpc/kasan: Fix addr error caused by page alignment",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26712",
    "datePublished": "2024-04-03T14:55:14.149Z",
    "dateReserved": "2024-02-19T14:20:24.159Z",
    "dateUpdated": "2026-08-05T11:26:49.646Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/230e89b5ad0a33f530a2a976b3e5e4385cb27882\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2738e0aa2fb24a7ab9c878d912dc2b239738c6c6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/0c09912dd8387e228afcc5e34ac5d79b1e3a1058\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/0516c06b19dc64807c10e01bb99b552bdf2d7dbe\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/70ef2ba1f4286b2b73675aeb424b590c92d57b25\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:14:12.618Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 4.4, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"HIGH\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26712\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-04-04T15:22:01.316380Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-23T19:01:21.993Z\"}}], \"cna\": {\"title\": \"powerpc/kasan: Fix addr error caused by page alignment\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerable code is `__init`/boot-time PPC32 KASAN shadow setup with no network-facing entry point; the resulting aliased page is exercised only by local kernel activity (allocations, module loads) on the affected machine.\\nAC:L - On a system that boots into the misaligned state, the corrupting writes are continuous and trivially driven \\u2014 any ordinary allocation/free path writes KASAN shadow bytes into the co-owned page, requiring no special timing, race, or memory layout the attacker must win.\\nPR:L - No elevated privilege is needed to drive the corruption; an unprivileged local process performing ordinary syscalls generates the kmalloc/kfree shadow poisoning that writes into the unreserved page, and running a KASAN kernel is a configuration precondition rather than a privilege the attacker exercises.\\nUI:N - The bad shadow mapping is established autonomously during boot and the corruption proceeds without any victim action.\\nS:U - Kernel memory corrupting other kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The unreserved page is aliased into the KASAN shadow window while simultaneously being allocated to arbitrary consumers (page cache, slab, user pages), so contents of other security contexts are exposed through the shadow mapping and the uncontrolled corruption is leverageable for disclosure.\\nI:H - This is out-of-bounds kernel writes into a page owned by unrelated code \\u2014 the commit explicitly states \\\"memory overwriting occurs\\\" \\u2014 corrupting live slab objects, page tables, or page cache, which is memory corruption exploitable for control-flow influence.\\nA:H - Silent overwriting of randomly allocated pages, including potential page tables and slab metadata, reliably produces oopses and kernel panics.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"663c0c9496a69f80011205ba3194049bcafd681d\", \"lessThan\": \"230e89b5ad0a33f530a2a976b3e5e4385cb27882\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"663c0c9496a69f80011205ba3194049bcafd681d\", \"lessThan\": \"2738e0aa2fb24a7ab9c878d912dc2b239738c6c6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"663c0c9496a69f80011205ba3194049bcafd681d\", \"lessThan\": \"0c09912dd8387e228afcc5e34ac5d79b1e3a1058\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"663c0c9496a69f80011205ba3194049bcafd681d\", \"lessThan\": \"0516c06b19dc64807c10e01bb99b552bdf2d7dbe\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"663c0c9496a69f80011205ba3194049bcafd681d\", \"lessThan\": \"70ef2ba1f4286b2b73675aeb424b590c92d57b25\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"663c0c9496a69f80011205ba3194049bcafd681d\", \"lessThan\": \"4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5ce93076d8ee2a0fac3ad4adbd2e91b6197146db\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.3.6\", \"lessThan\": \"5.4\", \"versionType\": \"semver\"}], \"programFiles\": [\"arch/powerpc/mm/kasan/init_32.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.4\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.4\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.210\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.149\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.79\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.18\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.6\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"arch/powerpc/mm/kasan/init_32.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/230e89b5ad0a33f530a2a976b3e5e4385cb27882\"}, {\"url\": \"https://git.kernel.org/stable/c/2738e0aa2fb24a7ab9c878d912dc2b239738c6c6\"}, {\"url\": \"https://git.kernel.org/stable/c/0c09912dd8387e228afcc5e34ac5d79b1e3a1058\"}, {\"url\": \"https://git.kernel.org/stable/c/0516c06b19dc64807c10e01bb99b552bdf2d7dbe\"}, {\"url\": \"https://git.kernel.org/stable/c/70ef2ba1f4286b2b73675aeb424b590c92d57b25\"}, {\"url\": \"https://git.kernel.org/stable/c/4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\npowerpc/kasan: Fix addr error caused by page alignment\\n\\nIn kasan_init_region, when k_start is not page aligned, at the begin of\\nfor loop, k_cur = k_start \u0026 PAGE_MASK is less than k_start, and then\\n`va = block + k_cur - k_start` is less than block, the addr va is invalid,\\nbecause the memory address space from va to block is not alloced by\\nmemblock_alloc, which will not be reserved by memblock_reserve later, it\\nwill be used by other places.\\n\\nAs a result, memory overwriting occurs.\\n\\nfor example:\\nint __init __weak kasan_init_region(void *start, size_t size)\\n{\\n[...]\\n\\t/* if say block(dcd97000) k_start(feef7400) k_end(feeff3fe) */\\n\\tblock = memblock_alloc(k_end - k_start, PAGE_SIZE);\\n\\t[...]\\n\\tfor (k_cur = k_start \u0026 PAGE_MASK; k_cur \u003c k_end; k_cur += PAGE_SIZE) {\\n\\t\\t/* at the begin of for loop\\n\\t\\t * block(dcd97000) va(dcd96c00) k_cur(feef7000) k_start(feef7400)\\n\\t\\t * va(dcd96c00) is less than block(dcd97000), va is invalid\\n\\t\\t */\\n\\t\\tvoid *va = block + k_cur - k_start;\\n\\t\\t[...]\\n\\t}\\n[...]\\n}\\n\\nTherefore, page alignment is performed on k_start before\\nmemblock_alloc() to ensure the validity of the VA address.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.210\", \"versionStartIncluding\": \"5.4\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.149\", \"versionStartIncluding\": \"5.4\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.79\", \"versionStartIncluding\": \"5.4\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.18\", \"versionStartIncluding\": \"5.4\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.6\", \"versionStartIncluding\": \"5.4\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"5.4\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.3.6\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:26:49.646Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26712\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:26:49.646Z\", \"dateReserved\": \"2024-02-19T14:20:24.159Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-03T14:55:14.149Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…