CVE-2024-26686: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats
fs/proc: dotaskstat: use sig->statslock to gather the threads/children stats
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.82 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7.6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.82.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.15.182.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26686?
CVE-2024-26686 has been classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-26686?
To fix CVE-2024-26686, upgrade your Linux kernel to versions 6.1.82, 6.7.6, or 6.8.
What systems are affected by CVE-2024-26686?
CVE-2024-26686 affects various versions of the Linux kernel and specific IBM Security Verify Governance products.
What is the impact of CVE-2024-26686?
The impact of CVE-2024-26686 involves potential issues related to thread and child statistics gathering within the Linux kernel.
When was CVE-2024-26686 disclosed?
CVE-2024-26686 was disclosed in April 2024 as part of a security update for the Linux kernel.