🛡️ AZL-59453 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-26841 affecting package kernel 5.15.200.1-1

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Update cpu_sibling_map when disabling nonboot CPUs

Update cpu_sibling_map when disabling nonboot CPUs by defining & calling

clear_cpu_sibling_map(), otherwise we get such errors on SMT systems:

jump label: negative count!

WARNING: CPU: 6 PID: 45 at kernel/jump_label.c:263 __static_key_slow_dec_cpuslocked+0xec/0x100

CPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340

pc 90000000004c302c ra 90000000004c302c tp 90000001005bc000 sp 90000001005bfd20

a0 000000000000001b a1 900000000224c278 a2 90000001005bfb58 a3 900000000224c280

a4 900000000224c278 a5 90000001005bfb50 a6 0000000000000001 a7 0000000000000001

t0 ce87a4763eb5234a t1 ce87a4763eb5234a t2 0000000000000000 t3 0000000000000000

t4 0000000000000006 t5 0000000000000000 t6 0000000000000064 t7 0000000000001964

t8 000000000009ebf6 u0 9000000001f2a068 s9 0000000000000000 s0 900000000246a2d8

s1 ffffffffffffffff s2 ffffffffffffffff s3 90000000021518c0 s4 0000000000000040

s5 9000000002151058 s6 9000000009828e40 s7 00000000000000b4 s8 0000000000000006

ra: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100

ERA: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100

CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)

PRMD: 00000004 (PPLV0 +PIE -PWE)

EUEN: 00000000 (-FPE -SXE -ASXE -BTE)

ECFG: 00071c1c (LIE=2-4,10-12 VS=7)

ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)

PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV)

CPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340

Stack : 0000000000000000 900000000203f258 900000000179afc8 90000001005bc000

90000001005bf980 0000000000000000 90000001005bf988 9000000001fe0be0

900000000224c280 900000000224c278 90000001005bf8c0 0000000000000001

0000000000000001 ce87a4763eb5234a 0000000007f38000 90000001003f8cc0

0000000000000000 0000000000000006 0000000000000000 4c206e6f73676e6f

6f4c203a656d616e 000000000009ec99 0000000007f38000 0000000000000000

900000000214b000 9000000001fe0be0 0000000000000004 0000000000000000

0000000000000107 0000000000000009 ffffffffffafdabe 00000000000000b4

0000000000000006 90000000004c302c 9000000000224528 00005555939a0c7c

00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c

...

Call Trace:

[<9000000000224528>] show_stack+0x48/0x1a0

[<900000000179afc8>] dump_stack_lvl+0x78/0xa0

[<9000000000263ed0>] __warn+0x90/0x1a0

[<90000000017419b8>] report_bug+0x1b8/0x280

[<900000000179c564>] do_bp+0x264/0x420

[<90000000004c302c>] __static_key_slow_dec_cpuslocked+0xec/0x100

[<90000000002b4d7c>] sched_cpu_deactivate+0x2fc/0x300

[<9000000000266498>] cpuhp_invoke_callback+0x178/0x8a0

[<9000000000267f70>] cpuhp_thread_fun+0xf0/0x240

[<90000000002a117c>] smpboot_thread_fn+0x1dc/0x2e0

[<900000000029a720>] kthread+0x140/0x160

[<9000000000222288>] ret_from_kernel_thread+0xc/0xa4

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

AZL-59453 is recorded against 1 package.

  • kernel

Timeline and source

Published on 17 April 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-04-17
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-59453?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-59453 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.