PT-2024-21452 · Linux+9 · Linux Kernel+9

Syzbot

·

Published

2024-04-02

·

Updated

2025-09-29

·

CVE-2024-26675

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.8.0-rc2-syzkaller-g41bccc98fb79
Description A vulnerability has been resolved in the Linux kernel. The issue is related to the ppp async module, where a warning was triggered by syzbot in alloc pages(). The warning is due to an order exceeding MAX PAGE ORDER. Willem fixed a similar issue in a previous commit, and the same sanity check has been adopted for ppp async ioctl(PPPIOCSMRU). The vulnerability is related to memory allocation and can be exploited by an attacker to potentially cause a denial-of-service or execute arbitrary code.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, update to a version later than 6.8.0-rc2-syzkaller-g41bccc98fb79. As a temporary workaround, consider disabling the ppp async module until a patch is available.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4352
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
CESA-2024_4211
CESA-2024_4352
CVE-2024-26675
DLA-3840-1
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_4211
INFSA-2024_4352
INFSA-2024_9315
OESA-2024-1617
OESA-2024-1618
OESA-2024-1647
OESA-2024-1648
OESA-2024-1649
OESA-2024-1650
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
RHSA-2024:4211
RHSA-2024:4352
RHSA-2024:9315
RHSA-2024_4211
RHSA-2024_4352
RHSA-2024_9315
RLSA-2024:4211
RLSA-2024:4352
RXSA-2024:4211
SUSE-SU-2024:1643-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:2135-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6767-1
USN-6767-2
USN-6795-1
USN-6828-1
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1
USN-7121-1
USN-7121-2
USN-7121-3
USN-7148-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu