CVE-2024-26686

    Dashboard / Vulnerabilities / CVE-2024-26686

    CVE-2024-26686

    Published: 3 Apr 2024Last Modified: 12 Aug 2026

    Summary: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats

    Details: In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. If NR_CPUS threads call do_task_stat() at the same time and the process has NR_THREADS, it will spin with irqs disabled O(NR_CPUS * NR_THREADS) time. Change do_task_stat() to use sig->stats_lock to gather the statistics outside of ->siglock protected section, in the likely case this code will run lockless.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

    Affected versions

    v5.15.180
    v5.15.179
    v5.15.178
    v5.15.177
    v5.15.176
    v5.15.175
    v5.15.174
    v5.15.173
    v5.15.172
    v5.15.171
    v5.15.170
    v5.15.169
    v5.15.168
    v5.15.167
    v5.15.166
    v5.15.165
    v5.15.164
    v5.15.163
    v5.15.162
    v5.15.161
    v5.15.160
    v5.15.159
    v5.15.158
    v5.15.157
    v5.15.156
    v5.15.155
    v5.15.154
    v5.15.153
    v5.15.152
    v5.15.151
    v5.15.150
    v5.15.149
    v5.15.148
    v5.15.147
    v5.15.146
    v5.15.145
    v5.15.144
    v5.15.143
    v5.15.142
    v5.15.141
    v5.15.140
    v5.15.139
    v5.15.138
    v5.15.137
    v5.15.136
    v5.15.135
    v5.15.134
    v5.15.133
    v5.15.132
    v5.15.131
    v5.15.130
    v5.15.129
    v5.15.128
    v5.15.127
    v5.15.126
    v5.15.125
    v5.15.124
    v5.15.123
    v5.15.122
    v5.15.121
    v5.15.120
    v5.15.119
    v5.15.118
    v5.15.117
    v5.15.116
    v5.15.115
    v5.15.114
    v5.15.113
    v5.15.112
    v5.15.111
    v5.15.110
    v5.15.109
    v5.15.108
    v5.15.107
    v5.15.106
    v5.15.105
    v5.15.104
    v5.15.103
    v5.15.102
    v5.15.101
    v5.15.100
    v5.15.99
    v5.15.98
    v5.15.97
    v5.15.96
    v5.15.95
    v5.15.94
    v5.15.93
    v5.15.92
    v5.15.91
    v5.15.90
    v5.15.89
    v5.15.88
    v5.15.87
    v5.15.86
    v5.15.85
    v5.15.84
    v5.15.83
    v5.15.82
    v5.15.81
    v5.15.80
    v5.15.79
    v5.15.78
    v5.15.77
    v5.15.76
    v5.15.75
    v5.15.74
    v5.15.73
    v5.15.72
    v5.15.71
    v5.15.70
    v5.15.69
    v5.15.68
    v5.15.67
    v5.15.66
    v5.15.65
    v5.15.64
    v5.15.63
    v5.15.62
    v5.15.61
    v5.15.60
    v5.15.59
    v5.15.58
    v5.15.57
    v5.15.56
    v5.15.55
    v5.15.54
    v5.15.53
    v5.15.52
    v5.15.51
    v5.15.50
    v5.15.49
    v5.15.48
    v5.15.47
    v5.15.46
    v5.15.45
    v5.15.44
    v5.15.43
    v5.15.42
    v5.15.41
    v5.15.40
    v5.15.39
    v5.15.38
    v5.15.37
    v5.15.36
    v5.15.35
    v5.15.34
    v5.15.33
    v5.15.32
    v5.15.31
    v5.15.30
    v5.15.29
    v5.15.28
    v5.15.27
    v5.15.26
    v5.15.25
    v5.15.24
    v5.15.23
    v5.15.22
    v5.15.21
    v5.15.20
    v5.15.19
    v5.15.18
    v5.15.17
    v5.15.16
    v5.15.15
    v5.15.14
    v5.15.13
    v5.15.12
    v5.15.11
    v5.15.10
    v5.15.9
    v5.15.8
    v5.15.7
    v5.15
    v5.15.6
    v5.15.5
    v5.15.4
    v5.15.3
    v5.15.2
    v5.15.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-26686 | CVE-DB