Wind River Support Network

HomeDefectsLIN1023-4630
Fixed

LIN1023-4630 : Security Advisory - linux - CVE-2024-26795

Created: Apr 5, 2024    Updated: Apr 20, 2024
Resolved Date: Apr 19, 2024
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

riscv: Sparse-Memory/vmemmap out-of-bounds fix

Offset vmemmap so that the first page of vmemmap will be mapped
to the first page of physical memory in order to ensure that
vmemmap’s bounds will be respected during
pfn_to_page()/page_to_pfn() operations.
The conversion macros will produce correct SV39/48/57 addresses
for every possible/valid DRAM_BASE inside the physical memory limits.

v2:Address Alex's comments

CREATE(Triage):(User=admin) CVE-2024-26795 (https://nvd.nist.gov/vuln/detail/CVE-2024-26795)

CVEs


Live chat
Online