Resource exhaustion in Linux kernel - CVE-2024-26621
Published: July 11, 2024
Vulnerability identifier: #VU94108
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26621
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to system forces huge page alignment on 32-bit systems in mm/huge_memory.c. A local user can perform a denial of service (DoS) attack.
Affected software
Linux kernel
Debian Linux
Amazon Linux AMI
kernel
linux (Debian package)
Debian Linux
Amazon Linux AMI
kernel
linux (Debian package)
How to mitigate CVE-2024-26621
Install updates from vendor's website.
kernel - update to 6.1.82-99.168
linux (Debian package) - update to 6.1.85-1
linux (Debian package) - update to 6.1.85-1
External References
- https://git.kernel.org/stable/c/7432376c913381c5f24d373a87ff629bbde94b47
- https://git.kernel.org/stable/c/4ef9ad19e17676b9ef071309bc62020e2373705d
- https://git.kernel.org/stable/c/87632bc9ecff5ded93433bc0fca428019bdd1cfe
- https://zolutal.github.io/aslrnt/
- http://www.openwall.com/lists/oss-security/2024/07/08/3
- http://www.openwall.com/lists/oss-security/2024/07/08/5
- http://www.openwall.com/lists/oss-security/2024/07/08/4
- http://www.openwall.com/lists/oss-security/2024/07/08/6
- http://www.openwall.com/lists/oss-security/2024/07/08/7
- http://www.openwall.com/lists/oss-security/2024/07/08/8
- http://www.openwall.com/lists/oss-security/2024/07/09/1
- http://www.openwall.com/lists/oss-security/2024/07/10/5
- http://www.openwall.com/lists/oss-security/2024/07/10/7
- http://www.openwall.com/lists/oss-security/2024/07/10/8