Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of pages in a soft-reserved region.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.10.211 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/156cb12ffdcf33883304f0db645e1eadae712fe0Patch
- https://git.kernel.org/stable/c/4aa36b62c3eaa869860bf78b1146e9f2b5f782a9Patch
- https://git.kernel.org/stable/c/4fff3d735baea104017f2e3c245e27cdc79f2426Patch
- https://git.kernel.org/stable/c/700c3f642c32721f246e09d3a9511acf40ae42bePatch
- https://git.kernel.org/stable/c/cf3d6813601fe496de7f023435e31bfffa74ae70Patch
- https://git.kernel.org/stable/c/de1034b38a346ef6be25fe8792f5d1e0684d5ff4Patch
- https://git.kernel.org/stable/c/156cb12ffdcf33883304f0db645e1eadae712fe0Patch
- https://git.kernel.org/stable/c/4aa36b62c3eaa869860bf78b1146e9f2b5f782a9Patch
- https://git.kernel.org/stable/c/4fff3d735baea104017f2e3c245e27cdc79f2426Patch
- https://git.kernel.org/stable/c/700c3f642c32721f246e09d3a9511acf40ae42bePatch
- https://git.kernel.org/stable/c/cf3d6813601fe496de7f023435e31bfffa74ae70Patch
- https://git.kernel.org/stable/c/de1034b38a346ef6be25fe8792f5d1e0684d5ff4Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing List
FAQ
What is CVE-2024-26843?
CVE-2024-26843 is a vulnerability with a CVSS score of 6.0 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of pages...
How severe is CVE-2024-26843?
CVE-2024-26843 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26843?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.