Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-26787

5.5 · MEDIUM
Published Apr 4, 2024 linux EPSS 0.23% (13th pctl)

Overview

CVE-2024-26787 is a medium-severity vulnerability affecting linux linux_kernel. It was published on April 4, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

mmc: mmci: stm32: fix DMA API overlapping mappings warning

Turning on CONFIG_DMA_API_DEBUG_SG results in the following warning:

DMA-API: mmci-pl18x 48220000.mmc: cacheline tracking EEXIST,

overlapping mappings aren't supported

WARNING: CPU: 1 PID: 51 at kernel/dma/debug.c:568

add_dma_entry+0x234/0x2f4

Modules linked in:

CPU: 1 PID: 51 Comm: kworker/1:2 Not tainted 6.1.28 #1

Hardware name: STMicroelectronics STM32MP257F-EV1 Evaluation Board (DT)

Workqueue: events_freezable mmc_rescan

Call trace:

add_dma_entry+0x234/0x2f4

debug_dma_map_sg+0x198/0x350

__dma_map_sg_attrs+0xa0/0x110

dma_map_sg_attrs+0x10/0x2c

sdmmc_idma_prep_data+0x80/0xc0

mmci_prep_data+0x38/0x84

mmci_start_data+0x108/0x2dc

mmci_request+0xe4/0x190

__mmc_start_request+0x68/0x140

mmc_start_request+0x94/0xc0

mmc_wait_for_req+0x70/0x100

mmc_send_tuning+0x108/0x1ac

sdmmc_execute_tuning+0x14c/0x210

mmc_execute_tuning+0x48/0xec

mmc_sd_init_uhs_card.part.0+0x20

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.20, < 5.10.213 Affected

Frequently Asked Questions

What is CVE-2024-26787?

CVE-2024-26787 is a medium-severity vulnerability affecting linux linux_kernel. It was published on April 4, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2024-26787?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-26787?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-26787?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-26787 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.