CVE-2024-26659

medium
Published 2024-04-02 · Modified 2024-06-05
CVSS v3
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
5.5

Description

RHSA-2024:3627: kernel-rt security and bug fix update (Moderate)

Predictions

Exploit likelihood
55%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description kernel: xhci: handle isoc Babble and Buffer Overrun events properly Red Hat statement Red Hat Product Security has classified the severity of this vulnerability as Moderate due to the specific prerequisites required for exploitation. Successful exploitation generally necessitates local access to the system with elevated permissions to interact with the Extensible Host Controller…

Description

kernel: xhci: handle isoc Babble and Buffer Overrun events properly

Red Hat statement

Red Hat Product Security has classified the severity of this vulnerability as Moderate due to the specific prerequisites required for exploitation. Successful exploitation generally necessitates local access to the system with elevated permissions to interact with the Extensible Host Controller Interface (xHCI) driver, which effectively translates to root-level access.

CVSS v3: 4.1 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10RHSA-2024:36272024-06-05T00:00:00Z
Red Hat Enterprise Linux 8kernel-0:4.18.0-553.5.1.el8_10RHSA-2024:36182024-06-05T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportkernel-0:5.14.0-427.81.1.el9_4RHSA-2025:131352025-08-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtFix deferred

Apply commands

bash fix
Apply RHSA-2024:3627 for Red Hat Enterprise Linux 8
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 9Affected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
suse slesaffected
debian debianbookwormfixed6.1.82-1
debian debianbullseyefixed5.10.216-1
debian debianforkyfixed6.7.7-1
debian debiansidfixed6.7.7-1
debian debiantrixiefixed6.7.7-1
linux linux-kernelaffected5.10.213
debian debian10.0affected
linux linux-kernel6.8affected
almalinux almalinux8fixedkernel-abi-stablelists-4.18.0-553.5.1.el8_10.noarch.rpm
redhat rhel8fixed

References

CWEs

CWE-787

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.