CVE-2024-46826
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/09/2024
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ELF: fix kernel.randomize_va_space double read<br />
<br />
ELF loader uses "randomize_va_space" twice. It is sysctl and can change<br />
at any moment, so 2 loads could see 2 different values in theory with<br />
unpredictable consequences.<br />
<br />
Issue exactly one load for consistent value across one exec.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.110 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.51 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.10.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1cf8cd80903073440b6ea055811d04edd24fe4f7
- https://git.kernel.org/stable/c/1f81d51141a234ad0a3874b4d185dc27a521cd27
- https://git.kernel.org/stable/c/2a97388a807b6ab5538aa8f8537b2463c6988bd2
- https://git.kernel.org/stable/c/53f17409abf61f66b6f05aff795e938e5ba811d1
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html



