CVE-2024-26653·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: usb: misc: ljca: Fix double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function ljca_auxdev_release calls kfree(auxdev->dev.platform_data) to free the parameter data of the function ljca_new_client_device. The callers of ljca_new_client_device shouldn't call kfree() again in the error handling path to free the platform data. Fix this by cleaning up the redundant kfree() in all callers and adding kfree() the passed in platform_data on errors which happen before auxiliary_device_init() succeeds .
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.8.3
- Published
- 2024-04-01
Affected versions
From: 6.8
Until: 6.8.3
Fixed in: 6.8.3
How to fix this CVE
Update your Linux kernel to version 6.8.3 or later to resolve a critical double-free memory corruption vulnerability in the USB LJCA driver's error handling path. This flaw can lead to kernel crashes or potential privilege escalation when the auxiliary device initialization fails. Apply the patch immediately to systems running kernel versions 6.8 through 6.8.2.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with `uname -r` and verify if it falls in the 6.8.0-6.8.2 range
- Step 2: Verify if the USB LJCA driver is loaded by running `lsmod | grep ljca` to determine if the vulnerable component is present
- Step 3: Search kernel logs for ljca-related errors using `sudo dmesg | grep -i ljca` or `sudo journalctl -u kernel | grep -i ljca`
- Step 4: After patching, confirm the new kernel version with `uname -r` and verify it shows 6.8.3 or later
FAQ
What is CVE-2024-26653?
CVE-2024-26653 is a double-free memory vulnerability in the Linux kernel's USB LJCA (Light Jewelry-like Control Architecture) device driver that occurs when auxiliary device initialization fails, potentially allowing kernel panic or code execution.
Is CVE-2024-26653 being actively exploited?
No, this vulnerability is not listed in the CISA KEV catalog and has no publicly available exploits, though the high CVSS score (7.8) indicates it warrants prompt patching.
What versions of Kernel are affected by CVE-2024-26653?
Linux kernel versions 6.8.0 through 6.8.2 are vulnerable; version 6.8.3 and later include the fix.
How do I check if my server is vulnerable to CVE-2024-26653?
Run `uname -r` to display your kernel version; if it shows 6.8.0, 6.8.1, or 6.8.2, your system is vulnerable. Additionally, check if the ljca driver is in use with `lsmod | grep ljca`.
Does Defensia detect CVE-2024-26653?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-26653 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/420babea4f1881a7c4ea22a8e218b8c6895d3f21
- https://git.kernel.org/stable/c/7c9631969287a5366bc8e39cd5abff154b35fb80
- https://git.kernel.org/stable/c/8a9f653cc852677003c23ee8075e3ed8fb4743c9
- https://git.kernel.org/stable/c/420babea4f1881a7c4ea22a8e218b8c6895d3f21
- https://git.kernel.org/stable/c/7c9631969287a5366bc8e39cd5abff154b35fb80
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-26653. Free for 1 server.
Get started free