Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-26765

5.5 · MEDIUM
Published Apr 3, 2024 linux EPSS 0.24% (14th pctl)

Overview

CVE-2024-26765 is a medium-severity vulnerability affecting linux linux_kernel. It was published on April 3, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Disable IRQ before init_fn() for nonboot CPUs

Disable IRQ before init_fn() for nonboot CPUs when hotplug, in order to

silence such warnings (and also avoid potential errors due to unexpected

interrupts):

WARNING: CPU: 1 PID: 0 at kernel/rcu/tree.c:4503 rcu_cpu_starting+0x214/0x280

CPU: 1 PID: 0 Comm: swapper/1 Not tainted 6.6.17+ #1198

pc 90000000048e3334 ra 90000000047bd56c tp 900000010039c000 sp 900000010039fdd0

a0 0000000000000001 a1 0000000000000006 a2 900000000802c040 a3 0000000000000000

a4 0000000000000001 a5 0000000000000004 a6 0000000000000000 a7 90000000048e3f4c

t0 0000000000000001 t1 9000000005c70968 t2 0000000004000000 t3 000000000005e56e

t4 00000000000002e4 t5 0000000000001000 t6 ffffffff80000000 t7 0000000000040000

t8 9000000007931638 u0 0000000000000006 s9 0000000000000004 s0 0000000000000001

s1 9000000006356ac0 s2 9000000007244000 s3 0000000000000001 s4 0000000000000001

s5 900000000636f000

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 0, < 6.1.80 Affected

Frequently Asked Questions

What is CVE-2024-26765?

CVE-2024-26765 is a medium-severity vulnerability affecting linux linux_kernel. It was published on April 3, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2024-26765?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-26765?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-26765?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-26765 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.