CVE-2024-26695
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Apr 3, 2024
Updated: Jan 7, 2025
CWE ID 476
Summary
CVE-2024-26695 is a vulnerability affecting the Linux kernel's crypto module, specifically the ccp driver. The issue involves a null pointer dereference in the function __sev_platform_shutdown_locked. This vulnerability can be triggered when the SEV platform device is shut down with a null psp_master, which can result in a general protection fault. The vulnerability was discovered using KASAN and can potentially lead to a system crash. The Linux kernel team has resolved this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Linux Kernel
- Debian
Affected Vendors
- LINUX
- Debian