PT-2024-7821 · Linux+9 · Linux Kernel+9

Alan Stern

·

Published

2024-04-11

·

Updated

2026-02-21

·

CVE-2024-26993

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to a reference leak in the sysfs break active protection() routine. When the call to kernfs find and get() fails, kn will be NULL, and the companion sysfs unbreak active protection() routine won't get called, resulting in an unreleased reference to kobj. This leak can be fixed by adding an explicit kobject put() call when kn is NULL. The vulnerability may allow an attacker to access confidential information.
Recommendations To resolve the issue, update to Linux kernel version 6.6.37 or later. As a temporary workaround, consider restricting access to the sysfs break active protection() function until a patch is available.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3618
ALSA-2024:3619
ALSA-2024:3627
ALSA-2025_16880
AZL-40511
BDU:2024-09321
CESA-2024_3618
CESA-2024_3627
CVE-2024-26993
DLA-3840-1
DLA-3842-1
DSA-5680-1
DSA-5681-1
INFSA-2024_3618
INFSA-2024_3619
INFSA-2024_3627
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1677
OESA-2024-1678
OESA-2024-1679
OESA-2024-1680
OESA-2024-1681
OESA-2024-1682
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
RHSA-2024:3460
RHSA-2024:3461
RHSA-2024:3618
RHSA-2024:3619
RHSA-2024:3627
RHSA-2024:4107
RHSA-2024:5256
RHSA-2024:5257
RHSA-2024:6206
RHSA-2024:7002
RHSA-2024:7003
RHSA-2024_3618
RHSA-2024_3619
RHSA-2024_3627
RLSA-2024:3618
RLSA-2024:3619
RLSA-2024:3627
SUSE-SU-2024:1643-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu