CVE-2024-26703

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
03/04/2024
Last modified:
27/02/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> tracing/timerlat: Move hrtimer_init to timerlat_fd open()<br /> <br /> Currently, the timerlat&amp;#39;s hrtimer is initialized at the first read of<br /> timerlat_fd, and destroyed at close(). It works, but it causes an error<br /> if the user program open() and close() the file without reading.<br /> <br /> Here&amp;#39;s an example:<br /> <br /> # echo NO_OSNOISE_WORKLOAD &gt; /sys/kernel/debug/tracing/osnoise/options<br /> # echo timerlat &gt; /sys/kernel/debug/tracing/current_tracer<br /> <br /> # cat

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.5 (including) 6.6.18 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.6 (excluding)
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*