CVE-2024-26946
Published: May 1, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy_from_kernel_nofault() in arch_adjust_kprobe_addr() because this function is used before checking the address is in text or not. Syzcaller bot found a bug and reported the case if user specifies inaccessible data area, arch_adjust_kprobe_addr() will cause a kernel panic. [ mingo: Clarified the comment. ]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected cc66bb91457827f62e2b6cb2518666820f0a6c48 - < 6417684315087904fffe8966d27ca74398c57dd6affected cc66bb91457827f62e2b6cb2518666820f0a6c48 - < f13edd1871d4fb4ab829aff629d47914e251bae3affected cc66bb91457827f62e2b6cb2518666820f0a6c48 - < 20fdb21eabaeb8f78f8f701f56d14ea0836ec861affected cc66bb91457827f62e2b6cb2518666820f0a6c48 - < b69f577308f1070004cafac106dd1a44099e5483affected cc66bb91457827f62e2b6cb2518666820f0a6c48 - < 4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b |
Linux | Linux | affected 5.18unaffected 0 - < 5.18unaffected 6.1.84 - <= 6.1.*unaffected 6.6.24 - <= 6.6.*unaffected 6.7.12 - <= 6.7.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now