CVE-2024-26622

Source
https://cve.org/CVERecord?id=CVE-2024-26622
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26622.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26622
Downstream
Related
Published
2024-03-04T06:40:01.754Z
Modified
2026-03-20T12:35:03.937241Z
Summary
tomoyo: fix UAF write bug in tomoyo_write_control()
Details

In the Linux kernel, the following vulnerability has been resolved:

tomoyo: fix UAF write bug in tomoyowritecontrol()

Since tomoyowritecontrol() updates head->writebuf when write() of long lines is requested, we need to fetch head->writebuf after head->io_sem is held. Otherwise, concurrent write() requests can cause use-after-free-write and double-free problems.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26622.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bd03a3e4c9a9df0c6b007045fa7fc8889111a478
Fixed
a23ac1788e2c828c097119e9a3178f0b7e503fee
Fixed
7d930a4da17958f869ef679ee0e4a8729337affc
Fixed
3bfe04c1273d30b866f4c7c238331ed3b08e5824
Fixed
2caa605079488da9601099fbda460cfc1702839f
Fixed
6edefe1b6c29a9932f558a898968a9fcbeec5711
Fixed
2f03fc340cac9ea1dc63cbf8c93dd2eb0f227815

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26622.json"