CVE-2024-26618
MEDIUMLinux Kernel - Resource Leak and State Corruption in SME Storage Allocation
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with existing storage When sme_alloc() is called with existing storage and we are not flushing we will always allocate new storage, both leaking the existing storage and corrupting the state. Fix this by separating the checks for flushing and for existing storage as we do for SVE. Callers that reallocate (eg, due to changing the vector length) should call sme_free() themselves.
References (5)
Core 5
Core References
Mailing List, Patch
https://git.kernel.org/stable/c/569156e4fa347237f8fa2a7e935d860109c55ac4
Mailing List, Patch
https://git.kernel.org/stable/c/814af6b4e6000e574e74d92197190edf07cc3680
Mailing List, Patch
https://git.kernel.org/stable/c/dc7eb8755797ed41a0d1b5c0c39df3c8f401b3d9
Scores
CVSS v3
5.5
EPSS
0.0024
EPSS Percentile
14.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (17)
linux/Kernel
< 6.1.140linux
linux/Kernel
6.2.0 - 6.6.15linux
linux/Kernel
6.5.0 - 6.7.3linux
Linux/Linux
< 6.5
Linux/Linux
21614ba60883eb93b99a7ee4b41cb927f93b39ae - f6421555dbd7cb3d4d70b69f33f998aaeca1e3b5
Linux/Linux
5d0a8d2fba50e9c07cde4aad7fba28c008b07a5b - 569156e4fa347237f8fa2a7e935d860109c55ac4
Linux/Linux
5d0a8d2fba50e9c07cde4aad7fba28c008b07a5b - 814af6b4e6000e574e74d92197190edf07cc3680
Linux/Linux
5d0a8d2fba50e9c07cde4aad7fba28c008b07a5b - dc7eb8755797ed41a0d1b5c0c39df3c8f401b3d9
Linux/Linux
6.1.140 - 6.1.*
Linux/Linux
6.1.47 - 6.1.140
... and 7 more
Published
Mar 11, 2024
Tracked Since
Feb 18, 2026