Exploitation of CVE-2024-26581 could allow sensitive information disclosure, privilege escalation, or arbitrary code execution
Summary
Exploitation of CVE-2024-26581 could allow sensitive information disclosure, privilege escalation, or arbitrary code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The Linux kernel contains an out-of-bounds write vulnerability CVE-2024-26581 with a CVSSv3 score of 7.8. If exploited, a local attacker could leak sensitive information, escalate privileges to root, or execute arbitrary code.
Remediation advice
Affected organisations are encouraged to contact their Linux IT vendors and update the Linux kernel to version 6.8-rc4 or higher.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 6 September 2024 12:20 pm