CVE-2024-26817

Source
https://cve.org/CVERecord?id=CVE-2024-26817
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26817.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26817
Downstream
Related
Published
2024-04-13T11:17:08.764Z
Modified
2026-05-28T03:54:30.143979807Z
Summary
amdkfd: use calloc instead of kzalloc to avoid integer overflow
Details

In the Linux kernel, the following vulnerability has been resolved:

amdkfd: use calloc instead of kzalloc to avoid integer overflow

This uses calloc instead of doing the multiplication which might overflow.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26817.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4a488a7ad71401169cecee75dc94bcce642e2c53
Fixed
e6721ea845fcb93a764a92bd40f1afc0d6c69751
Fixed
8b0564704255c6b3c6a7188e86939f754e1577c0
Fixed
fcbd99b3c73309107e3be71f20dff9414df64f91
Fixed
cbac7de1d9901521e78cdc34e15451df3611f2ad
Fixed
e6768c6737f4c02cba193a3339f0cc2907f0b86a
Fixed
315eb3c2df7e4cb18e3eacfa18a53a46f2bf0ef7
Fixed
0c33d11153949310d76631d8f4a4736519eacd3a
Fixed
3b0daecfeac0103aba8b293df07a0cbaf8b43f29

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26817.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.19.0
Fixed
4.19.312
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.274
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.215
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.155
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.86
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.27
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26817.json"