5.5 CVE-2024-46826

Patch
 

In the Linux kernel, the following vulnerability has been resolved: ELF: fix kernel.randomize_va_space double read ELF loader uses "randomize_va_space" twice. It is sysctl and can change at any moment, so 2 loads could see 2 different values in theory with unpredictable consequences. Issue exactly one load for consistent value across one exec.
https://nvd.nist.gov/vuln/detail/CVE-2024-46826

Categories

CWE-NVD-noinfo

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* < 6.1.110
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.2 < 6.6.51
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.7 < 6.10.10


REMEDIATION


Patch

Url
https://git.kernel.org/stable/c/1cf8cd80903073440b6ea055811d04edd24fe4f7
https://git.kernel.org/stable/c/1f81d51141a234ad0a3874b4d185dc27a521cd27
https://git.kernel.org/stable/c/2a97388a807b6ab5538aa8f8537b2463c6988bd2
https://git.kernel.org/stable/c/53f17409abf61f66b6f05aff795e938e5ba811d1


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry