Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-26823— irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems

CVSS 7.8 · High EPSS 0.23% · P14

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux9585a495ac936049dba141e8f9d99159ca06d46a< 91a80fff3eeed928b6fba21271f6a9719b22a5d8affected
9585a495ac936049dba141e8f9d99159ca06d46a< 4c60c611441f1f1e5de8e00e98ee5a4970778a00affected
9585a495ac936049dba141e8f9d99159ca06d46a< 8b02da04ad978827e5ccd675acf170198f747a7aaffected
6.6affected
< 6.6unaffected
6.6.18≤ 6.6.*unaffected
6.7.6≤ 6.7.*unaffected
6.8≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-26823

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems While refactoring the way the ITSs are probed, the handling of quirks applicable to ACPI-based platforms was lost. As a result, systems such as HIP07 lose their GICv4 functionnality, and some other may even fail to boot, unless they are configured to boot with DT. Move the enabling of quirks into its_probe_one(), making it common to all firmware implementations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 9585a495ac936049dba141e8f9d99159ca06d46a ~ 91a80fff3eeed928b6fba21271f6a9719b22a5d8 -
LinuxLinux 6.6 -

II. Public POCs for CVE-2024-26823

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26823

登录查看更多情报信息。

Other References for CVE-2024-26823 (3)

Same Patch Batch · Linux · 2024-04-17 · 100 CVEs total

CVE-2024-268539.8 CRITICALigc: avoid returning frame twice in XDP_REDIRECT
CVE-2024-268779.8 CRITICALcrypto: xilinx - call finalize with bh disabled
CVE-2024-268289.4 CRITICALcifs: fix underflow in parse_server_interfaces()
CVE-2024-268568.8 HIGHnet: sparx5: Fix use after free inside sparx5_del_mact_entry
CVE-2024-268228.7 HIGHsmb: client: set correct id, uid and cruid for multiuser automounts
CVE-2024-268308.4 HIGHi40e: Do not allow untrusted VF to remove administratively set MAC
CVE-2024-268907.8 HIGHBluetooth: btrtl: fix out of bounds memory access
CVE-2024-269197.8 HIGHusb: ulpi: Fix debugfs directory leak
CVE-2024-268847.8 HIGHbpf: Fix hashtab overflow check on 32-bit arches
CVE-2024-268837.8 HIGHbpf: Fix stackmap overflow check on 32-bit arches
CVE-2024-268697.8 HIGHf2fs: fix to truncate meta inode pages forcely
CVE-2024-268247.8 HIGHcrypto: algif_hash - Remove bogus SGL free on zero-length error path
CVE-2024-269117.8 HIGHdrm/buddy: Fix alloc_range() error handling code
CVE-2024-268387.8 HIGHRDMA/irdma: Fix KASAN issue with tasklet
CVE-2024-268657.8 HIGHrds: tcp: Fix use-after-free of net in reqsk_timer_handler().
CVE-2024-268647.8 HIGHtcp: Fix refcnt handling in __inet_hash_connect().
CVE-2024-268727.8 HIGHRDMA/srpt: Do not register event handler until srpt device is fully setup
CVE-2024-268957.8 HIGHwifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces
CVE-2024-268527.8 HIGHnet/ipv6: avoid possible UAF in ip6_route_mpath_notify()
CVE-2024-268987.8 HIGHaoe: fix the potential use-after-free problem in aoecmd_cfg_pkts

Showing top 20 of 100 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26823

No comments yet


Leave a comment