Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem might be triggered on systems with more than 128 cores per package.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.19.264, < 4.19.307 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8bPatch
- https://git.kernel.org/stable/c/3a7753bda55985dc26fae17795cb10d825453ad1Patch
- https://git.kernel.org/stable/c/4e440abc894585a34c2904a32cd54af1742311b3Patch
- https://git.kernel.org/stable/c/853a6503c586a71abf27e60a7f8c4fb28092976dPatch
- https://git.kernel.org/stable/c/93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6aPatch
- https://git.kernel.org/stable/c/9bce69419271eb8b2b3ab467387cb59c99d80debPatch
- https://git.kernel.org/stable/c/a16afec8e83c56b14a4a73d2e3fb8eec3a8a057ePatch
- https://git.kernel.org/stable/c/f0da068c75c20ffc5ba28243ff577531dc2af1fdPatch
- https://git.kernel.org/stable/c/1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8bPatch
- https://git.kernel.org/stable/c/3a7753bda55985dc26fae17795cb10d825453ad1Patch
- https://git.kernel.org/stable/c/4e440abc894585a34c2904a32cd54af1742311b3Patch
- https://git.kernel.org/stable/c/853a6503c586a71abf27e60a7f8c4fb28092976dPatch
- https://git.kernel.org/stable/c/93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6aPatch
- https://git.kernel.org/stable/c/9bce69419271eb8b2b3ab467387cb59c99d80debPatch
- https://git.kernel.org/stable/c/a16afec8e83c56b14a4a73d2e3fb8eec3a8a057ePatch
FAQ
What is CVE-2024-26664?
CVE-2024-26664 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem m...
How severe is CVE-2024-26664?
CVE-2024-26664 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26664?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.