Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-26618
HistoryMar 11, 2024 - 12:00 a.m.

CVE-2024-26618

2024-03-1100:00:00
ubuntu.com
ubuntu.com
6
cve-2024-26618
linux kernel
vulnerability
arm64/sme
allocation
fix
existing storage
state corruption
sve
vector length
unix

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%

In the Linux kernel, the following vulnerability has been resolved:
arm64/sme: Always exit sme_alloc() early with existing storage When
sme_alloc() is called with existing storage and we are not flushing we will
always allocate new storage, both leaking the existing storage and
corrupting the state. Fix this by separating the checks for flushing and
for existing storage as we do for SVE. Callers that reallocate (eg, due to
changing the vector length) should call sme_free() themselves.

Notes

Author Note
rodrigo-zaiden USN-6765-1 for linux-oem-6.5 wrongly stated that this CVE was fixed in version 6.5.0-1022.23. The mentioned notice was revoked and the state of the fix for linux-oem-6.5 was recovered to the previous state.
Rows per page:
1-10 of 201

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%