UBUNTU-CVE-2024-26686
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-26686
UBUNTU-CVE-2024-26686
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. If NR_CPUS threads call do_task_stat() at the same time and the process has NR_THREADS, it will spin with irqs disabled O(NR_CPUS * NR_THREADS) time. Change do_task_stat() to use sig->stats_lock to gather the statistics outside of ->siglock protected section, in the likely case this code will run lockless.
References: https://ubuntu.com/security/CVE-2024-26686, https://git.kernel.org/linus/7601df8031fd67310af891897ef6cc0df4209305, https://git.kernel.org/stable/c/cf4b8c39b9a0bd81c47afc7ef62914a62dd5ec4d, https://git.kernel.org/stable/c/27978243f165b44e342f28f449b91327944ea071, https://git.kernel.org/stable/c/7601df8031fd67310af891897ef6cc0df4209305, https://www.cve.org/CVERecord?id=CVE-2024-26686, https://ubuntu.com/security/notices/USN-7654-1, https://ubuntu.com/security/notices/USN-7654-2, https://ubuntu.com/security/notices/USN-7654-3, https://ubuntu.com/security/notices/USN-7655-1, https://ubuntu.com/security/notices/USN-7654-4, https://ubuntu.com/security/notices/USN-7654-5, https://ubuntu.com/security/notices/USN-7686-1, https://ubuntu.com/security/notices/USN-7711-1, https://ubuntu.com/security/notices/USN-7712-1, https://ubuntu.com/security/notices/USN-7712-2
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
