Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2024-26836
HistoryApr 17, 2024 - 10:10 a.m.

CVE-2024-26836 platform/x86: think-lmi: Fix password opcode ordering for workstations

2024-04-1710:10:03
Linux
github.com
5
linux kernel
platform/x86
think-lmi
password opcode
workstations
lenovo
attribute value
admin password
thinkpads
vulnerability fix

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: think-lmi: Fix password opcode ordering for workstations

The Lenovo workstations require the password opcode to be run before
the attribute value is changed (if Admin password is enabled).

Tested on some Thinkpads to confirm they are OK with this order too.

CNA Affected

[
  {
    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
    "vendor": "Linux",
    "product": "Linux",
    "versions": [
      {
        "status": "affected",
        "version": "640a5fa50a42",
        "lessThan": "2bfbe1e0aed0",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "640a5fa50a42",
        "lessThan": "6f7d0f5fd8e4",
        "versionType": "git"
      }
    ],
    "programFiles": [
      "drivers/platform/x86/think-lmi.c"
    ],
    "defaultStatus": "unaffected"
  },
  {
    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
    "vendor": "Linux",
    "product": "Linux",
    "versions": [
      {
        "status": "affected",
        "version": "5.17"
      },
      {
        "status": "unaffected",
        "version": "0",
        "lessThan": "5.17",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "6.7.7",
        "versionType": "custom",
        "lessThanOrEqual": "6.7.*"
      },
      {
        "status": "unaffected",
        "version": "6.8",
        "versionType": "original_commit_for_fix",
        "lessThanOrEqual": "*"
      }
    ],
    "programFiles": [
      "drivers/platform/x86/think-lmi.c"
    ],
    "defaultStatus": "affected"
  }
]

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial