CVE-2024-26618

    Dashboard / Vulnerabilities / CVE-2024-26618

    CVE-2024-26618

    Published: 29 Feb 2024Last Modified: 8 Oct 2026

    Summary: arm64/sme: Always exit sme_alloc() early with existing storage

    Details: In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with existing storage When sme_alloc() is called with existing storage and we are not flushing we will always allocate new storage, both leaking the existing storage and corrupting the state. Fix this by separating the checks for flushing and for existing storage as we do for SVE. Callers that reallocate (eg, due to changing the vector length) should call sme_free() themselves.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 21614ba60883eb93b99a7ee4b41cb927f93b39ae

    Affected versions

    v6.1.139
    v6.1.138
    v6.1.137
    v6.1.136
    v6.1.135
    v6.1.134
    v6.1.133
    v6.1.132
    v6.1.131
    v6.1.130
    v6.1.129
    v6.1.128
    v6.1.127
    v6.1.126
    v6.1.125
    v6.1.124
    v6.1.123
    v6.1.122
    v6.1.121
    v6.1.120
    v6.1.119
    v6.1.118
    v6.1.117
    v6.1.116
    v6.1.115
    v6.1.114
    v6.1.113
    v6.1.112
    v6.1.111
    v6.1.110
    v6.1.109
    v6.1.108
    v6.1.107
    v6.1.106
    v6.1.105
    v6.1.104
    v6.1.103
    v6.1.102
    v6.1.101
    v6.1.100
    v6.1.99
    v6.1.98
    v6.1.97
    v6.1.96
    v6.1.95
    v6.1.94
    v6.1.93
    v6.1.92
    v6.1.91
    v6.1.90
    v6.1.89
    v6.1.88
    v6.1.87
    v6.1.86
    v6.1.85
    v6.1.84
    v6.1.83
    v6.1.82
    v6.1.81
    v6.1.80
    v6.1.79
    v6.1.78
    v6.1.77
    v6.1.76
    v6.1.75
    v6.1.74
    v6.1.73
    v6.1.72
    v6.1.71
    v6.1.70
    v6.1.69
    v6.1.68
    v6.1.67
    v6.1.66
    v6.1.65
    v6.1.64
    v6.1.63
    v6.1.62
    v6.1.61
    v6.1.60
    v6.1.59
    v6.1.58
    v6.1.57
    v6.1.56
    v6.1.55
    v6.1.54
    v6.1.53
    v6.1.52
    v6.1.51
    v6.1.50
    v6.1.49
    v6.1.48
    v6.1.47

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-26618 | CVE-DB