CVE-2024-26695

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 3, 2024
Updated: Jan 7, 2025
CWE ID 476

Summary

CVE-2024-26695 is a vulnerability affecting the Linux kernel's crypto module, specifically the ccp driver. The issue involves a null pointer dereference in the function __sev_platform_shutdown_locked. This vulnerability can be triggered when the SEV platform device is shut down with a null psp_master, which can result in a general protection fault. The vulnerability was discovered using KASAN and can potentially lead to a system crash. The Linux kernel team has resolved this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Linux Kernel
  • Debian

Affected Vendors

  • LINUX
  • Debian