#VU93844 Resource management error in Linux kernel


Published: 2024-07-07

Vulnerability identifier: #VU93844

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-26764

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the kiocb_set_cancel_fn() and aio_prep_rw() functions in fs/aio.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/337b543e274fe7a8f47df3c8293cc6686ffa620f
http://git.kernel.org/stable/c/b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942
http://git.kernel.org/stable/c/ea1cd64d59f22d6d13f367d62ec6e27b9344695f
http://git.kernel.org/stable/c/d7b6fa97ec894edd02f64b83e5e72e1aa352f353
http://git.kernel.org/stable/c/18f614369def2a11a52f569fe0f910b199d13487
http://git.kernel.org/stable/c/e7e23fc5d5fe422827c9a43ecb579448f73876c7
http://git.kernel.org/stable/c/1dc7d74fe456944a9b1c57bd776280249f441ac6
http://git.kernel.org/stable/c/b820de741ae48ccf50dd95e297889c286ff4f760
http://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
http://lists.debian.org/debian-lts-announce/2024/06/msg00020.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability