PT-2024-3427 · Linux+5 · Linux Kernel+5

Published

2024-04-02

·

Updated

2025-09-29

·

CVE-2024-26817

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.8.5
Description: The issue is related to an integer overflow in the kfd ioctl get process apertures new() function in the amdkfd module of the Linux kernel. This overflow can be exploited to cause a denial of service. The vulnerability is resolved by using calloc instead of kzalloc to avoid the integer overflow.
Recommendations: For Linux kernel versions prior to 6.8.5, upgrade the kernel to a patched version to resolve the issue. Additionally, audit systems using affected versions for signs of exploit and ensure strong network segmentation to limit the local attack surface. As a temporary workaround, consider restricting access to the amdkfd module until a patch is available.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_10939
ALSA-2024_11486
ALSA-2024_1607
ALSA-2024_2394
ALSA-2025_1067
ALSA-2025_1068
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-03712
CVE-2024-26817
DLA-3840-1
DLA-3842-1
DSA-5680-1
DSA-5681-1
MGASA-2024-0141
MGASA-2024-0142
OESA-2024-1617
OESA-2024-1618
OESA-2024-1619
OESA-2024-1620
OESA-2024-1621
OESA-2024-1622
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
SUSE-SU-2024:1643-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1
SUSE-SU-2024:1870-1
SUSE-SU-2024_1643-1
SUSE-SU-2024_1644-1
SUSE-SU-2024_1646-1
SUSE-SU-2024_1648-1
SUSE-SU-2024_1648-2
SUSE-SU-2024_1659-1
SUSE-SU-2024_1663-1
SUSE-SU-2024_1870-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu