Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP boundaries") caused two issues [1] [2] reported on 32 bit system or compat userspace. It doesn't make too much sense to force huge page alignment on 32 bit system due to the constrained virtual address space. [1] https://lore.kernel.org/linux-mm/[email protected]/ [2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.18, < 6.1.81 |
References
- https://git.kernel.org/stable/c/4ef9ad19e17676b9ef071309bc62020e2373705dPatch
- https://git.kernel.org/stable/c/6ea9aa8d97e6563676094cb35755884173269555Patch
- https://git.kernel.org/stable/c/7432376c913381c5f24d373a87ff629bbde94b47Patch
- https://git.kernel.org/stable/c/87632bc9ecff5ded93433bc0fca428019bdd1cfePatch
- http://www.openwall.com/lists/oss-security/2024/07/08/3Patch
- http://www.openwall.com/lists/oss-security/2024/07/08/4Patch
- http://www.openwall.com/lists/oss-security/2024/07/08/5Patch
- http://www.openwall.com/lists/oss-security/2024/07/08/6Patch
- http://www.openwall.com/lists/oss-security/2024/07/08/7Patch
- http://www.openwall.com/lists/oss-security/2024/07/08/8Patch
- http://www.openwall.com/lists/oss-security/2024/07/09/1Patch
- http://www.openwall.com/lists/oss-security/2024/07/10/5Patch
- http://www.openwall.com/lists/oss-security/2024/07/10/7Patch
- http://www.openwall.com/lists/oss-security/2024/07/10/8Patch
- http://www.openwall.com/lists/oss-security/2024/07/11/4Patch
FAQ
What is CVE-2024-26621?
CVE-2024-26621 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align larger anonymous mappings on THP bounda...
How severe is CVE-2024-26621?
CVE-2024-26621 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26621?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.