Tracker / CVE-2024-26824
CVE-2024-26824
High 7.8
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - Remove bogus SGL free on zero-length error path When a zero-length message is hashed by algif_hash, and an error is triggered, it tries to free an SG list that was never allocated in the first place. Fix this by not freeing the SG list on the zero-length error path.
Affected products and versions
| linux | linux_kernel |
|---|---|
| linux | linux_kernel · 6.5 → 6.6.18 |
| linux | linux_kernel · 6.7 → 6.7.6 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.