#VU93844 Resource management error in Linux kernel - CVE-2024-26764


Vulnerability identifier: #VU93844

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-26764

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the kiocb_set_cancel_fn() and aio_prep_rw() functions in fs/aio.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/337b543e274fe7a8f47df3c8293cc6686ffa620f
https://git.kernel.org/stable/c/b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942
https://git.kernel.org/stable/c/ea1cd64d59f22d6d13f367d62ec6e27b9344695f
https://git.kernel.org/stable/c/d7b6fa97ec894edd02f64b83e5e72e1aa352f353
https://git.kernel.org/stable/c/18f614369def2a11a52f569fe0f910b199d13487
https://git.kernel.org/stable/c/e7e23fc5d5fe422827c9a43ecb579448f73876c7
https://git.kernel.org/stable/c/1dc7d74fe456944a9b1c57bd776280249f441ac6
https://git.kernel.org/stable/c/b820de741ae48ccf50dd95e297889c286ff4f760
https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability