Skip to main content

Exploitation of CVE-2024-26581 could allow sensitive information disclosure, privilege escalation, or arbitrary code execution

Summary

Exploitation of CVE-2024-26581 could allow sensitive information disclosure, privilege escalation, or arbitrary code execution

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

The Linux kernel contains an out-of-bounds write vulnerability CVE-2024-26581 with a CVSSv3 score of 7.8. If exploited, a local attacker could leak sensitive information, escalate privileges to root, or execute arbitrary code.

Remediation advice

Affected organisations are encouraged to contact their Linux IT vendors and update the Linux kernel to version 6.8-rc4 or higher.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 6 September 2024 12:20 pm