Review reviewHigh

CVE-2024-26664

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem might be triggered on systems with more than 128 cores per package.

CVSS
7.1
EPSS
0.25%
16.2% percentile
CISA KEV
Not listed
Published
2024.04.02
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.25%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem might be triggered on systems with more than 128 cores per package.

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 4f9dcadc55c21b39b072bb0882362c7edc4340bc < 93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6a, >= c00cdfc9bd767ee743ad3a4054de17aeb0afcbca < 1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8b, >= d9f0159da05df869071164edf0c6d7302efc5eca < f0da068c75c20ffc5ba28243ff577531dc2af1fd, >= 30cf0dee372baf9b515f2d9c7218f905fddf3cdb < a16afec8e83c56b14a4a73d2e3fb8eec3a8a057e, >= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 9bce69419271eb8b2b3ab467387cb59c99d80deb, >= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 853a6503c586a71abf27e60a7f8c4fb28092976d, >= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 3a7753bda55985dc26fae17795cb10d825453ad1, >= 7108b80a542b9d65e44b36d64a700a83658c0b73 < 4e440abc894585a34c2904a32cd54af1742311b3, >= d1de8e1ae924d9dc31548676e4a665b52ebee27e, >= 4.19.264 < 4.19.307, >= 5.4.221 < 5.4.269, >= 5.10.152 < 5.10.210, >= 5.15.76 < 5.15.149, >= 6.0.6 < 6.1, >= 6.1, >= 6.1 < 6.1.78, >= 6.2 < 6.6.17, >= 6.7 < 6.7.5, 6.8, 10.0
Fixed versions
4.19.307, 5.4.269, 5.10.210, 6.1.78, 6.6.17, 6.7.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-787
CVE-2024-26664 — Linux Linux, linux kernel, debian linux | SECUFOCUS NOW