We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)
Bugpilot (Bug tracking)

Ok

THREATINT CVE Home CVE Diag Help
PUBLISHED

CVE-2024-26753

crypto: virtio/akcipher - Fix stack overflow on memcpy

Reserved:2024-02-19
Published:2024-04-03
Updated:2024-04-04

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: virtio/akcipher - Fix stack overflow on memcpy sizeof(struct virtio_crypto_akcipher_session_para) is less than sizeof(struct virtio_crypto_op_ctrl_req::u), copying more bytes from stack variable leads stack overflow. Clang reports this issue by commands: make -j CC=clang-14 mrproper >/dev/null 2>&1 make -j O=/tmp/crypto-build CC=clang-14 allmodconfig >/dev/null 2>&1 make -j O=/tmp/crypto-build W=1 CC=clang-14 drivers/crypto/virtio/ virtio_crypto_akcipher_algs.o

Product status

Default status
unaffected

1ff57428894f before 37077ed16c77
affected

59ca6c93387d before 62f361bfea60
affected

59ca6c93387d before b0365460e945
affected

59ca6c93387d before ef1e47d50324
affected

59ca6c93387d before c0ec2a712daf
affected

Default status
affected

5.18
affected

Any version before 5.18
unaffected

5.10.212
unaffected

6.1.80
unaffected

6.6.19
unaffected

6.7.7
unaffected

6.8
unaffected

References

https://git.kernel.org/stable/c/37077ed16c7793e21b005979d33f8a61565b7e86

https://git.kernel.org/stable/c/62f361bfea60c6afc3df09c1ad4152e6507f6f47

https://git.kernel.org/stable/c/b0365460e945e1117b47cf7329d86de752daff63

https://git.kernel.org/stable/c/ef1e47d50324e232d2da484fe55a54274eeb9bc1

https://git.kernel.org/stable/c/c0ec2a712daf133d9996a8a1b7ee2d4996080363

cve.org CVE-2024-26753

nvd.nist.gov CVE-2024-26753

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-26753