CVE-2024-26836

HIGH

Linux kernel - Privilege Escalation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix password opcode ordering for workstations The Lenovo workstations require the password opcode to be run before the attribute value is changed (if Admin password is enabled). Tested on some Thinkpads to confirm they are OK with this order too.

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 14.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 5.17.0 - 6.6.55linux
linux/Kernel 6.7.0 - 6.7.7linux
Linux/Linux < 5.17
Linux/Linux 5.17
Linux/Linux 6.6.55 - 6.6.*
Linux/Linux 6.7.7 - 6.7.*
Linux/Linux 6.8
Linux/Linux 640a5fa50a42b99bfa2a0ec51b4ea9591d9bd055 - 2bfbe1e0aed00ba51d58573c79452fada3f62ed4
Linux/Linux 640a5fa50a42b99bfa2a0ec51b4ea9591d9bd055 - 2deb10a99671afda30f834e95e5b992a805bba6a
Linux/Linux 640a5fa50a42b99bfa2a0ec51b4ea9591d9bd055 - 6f7d0f5fd8e440c3446560100ac4ff9a55eec340
... and 2 more
Published Apr 17, 2024
Tracked Since Feb 18, 2026