CVE Database
/

CVE-2024-26946

Back to search

CVE-2024-26946

Published: May 1, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy_from_kernel_nofault() in arch_adjust_kprobe_addr() because this function is used before checking the address is in text or not. Syzcaller bot found a bug and reported the case if user specifies inaccessible data area, arch_adjust_kprobe_addr() will cause a kernel panic. [ mingo: Clarified the comment. ]

VendorProductVersions

Linux

Linux

affected
cc66bb91457827f62e2b6cb2518666820f0a6c48 - < 6417684315087904fffe8966d27ca74398c57dd6
affected
cc66bb91457827f62e2b6cb2518666820f0a6c48 - < f13edd1871d4fb4ab829aff629d47914e251bae3
affected
cc66bb91457827f62e2b6cb2518666820f0a6c48 - < 20fdb21eabaeb8f78f8f701f56d14ea0836ec861
affected
cc66bb91457827f62e2b6cb2518666820f0a6c48 - < b69f577308f1070004cafac106dd1a44099e5483
affected
cc66bb91457827f62e2b6cb2518666820f0a6c48 - < 4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b

Linux

Linux

affected
5.18
unaffected
0 - < 5.18
unaffected
6.1.84 - <= 6.1.*
unaffected
6.6.24 - <= 6.6.*
unaffected
6.7.12 - <= 6.7.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now