Wind River Support Network

HomeDefectsLIN1021-8002
Fixed

LIN1021-8002 : Security Advisory - linux - CVE-2024-26705

Created: Apr 3, 2024    Updated: Jun 12, 2024
Resolved Date: Jun 12, 2024
Found In Version: 10.21.20.1
Fix Version: 10.21.20.22
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

parisc: BTLB: Fix crash when setting up BTLB at CPU bringup

When using hotplug and bringing up a 32-bit CPU, ask the firmware about the
BTLB information to set up the static (block) TLB entries.

For that write access to the static btlb_info struct is needed, but
since it is marked __ro_after_init the kernel segfaults with missing
write permissions.

Fix the crash by dropping the __ro_after_init annotation.

CREATE(Triage):(User=admin) CVE-2024-26705 (https://nvd.nist.gov/vuln/detail/CVE-2024-26705)

CVEs


Live chat
Online