CVE-2024-26795
MEDIUMLinux Kernel - Memory Corruption via Incorrect vmemmap Offset Calculation
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: riscv: Sparse-Memory/vmemmap out-of-bounds fix Offset vmemmap so that the first page of vmemmap will be mapped to the first page of physical memory in order to ensure that vmemmap’s bounds will be respected during pfn_to_page()/page_to_pfn() operations. The conversion macros will produce correct SV39/48/57 addresses for every possible/valid DRAM_BASE inside the physical memory limits. v2:Address Alex's comments
References (7)
Core 7
Core References
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (22)
debian/debian_linux
10.0
linux/Kernel
5.11.0 - 5.15.151linux
linux/Kernel
5.16.0 - 6.1.81linux
linux/Kernel
5.4.0 - 5.10.212linux
linux/Kernel
6.2.0 - 6.6.21linux
linux/Kernel
6.7.0 - 6.7.9linux
Linux/Linux
< 5.4
Linux/Linux
5.10.212 - 5.10.*
Linux/Linux
5.15.151 - 5.15.*
Linux/Linux
5.4
... and 12 more
Published
Apr 04, 2024
Tracked Since
Feb 18, 2026