{"id":"DEBIAN-CVE-2024-26957","details":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: fix reference counting on zcrypt card objects  Tests with hot-plugging crytpo cards on KVM guests with debug kernel build revealed an use after free for the load field of the struct zcrypt_card. The reason was an incorrect reference handling of the zcrypt card object which could lead to a free of the zcrypt card object while it was still in use.  This is an example of the slab message:      kernel: 0x00000000885a7512-0x00000000885a7513 @offset=1298. First byte 0x68 instead of 0x6b     kernel: Allocated in zcrypt_card_alloc+0x36/0x70 [zcrypt] age=18046 cpu=3 pid=43     kernel:  kmalloc_trace+0x3f2/0x470     kernel:  zcrypt_card_alloc+0x36/0x70 [zcrypt]     kernel:  zcrypt_cex4_card_probe+0x26/0x380 [zcrypt_cex4]     kernel:  ap_device_probe+0x15c/0x290     kernel:  really_probe+0xd2/0x468     kernel:  driver_probe_device+0x40/0xf0     kernel:  __device_attach_driver+0xc0/0x140     kernel:  bus_for_each_drv+0x8c/0xd0     kernel:  __device_attach+0x114/0x198     kernel:  bus_probe_device+0xb4/0xc8     kernel:  device_add+0x4d2/0x6e0     kernel:  ap_scan_adapter+0x3d0/0x7c0     kernel:  ap_scan_bus+0x5a/0x3b0     kernel:  ap_scan_bus_wq_callback+0x40/0x60     kernel:  process_one_work+0x26e/0x620     kernel:  worker_thread+0x21c/0x440     kernel: Freed in zcrypt_card_put+0x54/0x80 [zcrypt] age=9024 cpu=3 pid=43     kernel:  kfree+0x37e/0x418     kernel:  zcrypt_card_put+0x54/0x80 [zcrypt]     kernel:  ap_device_remove+0x4c/0xe0     kernel:  device_release_driver_internal+0x1c4/0x270     kernel:  bus_remove_device+0x100/0x188     kernel:  device_del+0x164/0x3c0     kernel:  device_unregister+0x30/0x90     kernel:  ap_scan_adapter+0xc8/0x7c0     kernel:  ap_scan_bus+0x5a/0x3b0     kernel:  ap_scan_bus_wq_callback+0x40/0x60     kernel:  process_one_work+0x26e/0x620     kernel:  worker_thread+0x21c/0x440     kernel:  kthread+0x150/0x168     kernel:  __ret_from_fork+0x3c/0x58     kernel:  ret_from_fork+0xa/0x30     kernel: Slab 0x00000372022169c0 objects=20 used=18 fp=0x00000000885a7c88 flags=0x3ffff00000000a00(workingset|slab|node=0|zone=1|lastcpupid=0x1ffff)     kernel: Object 0x00000000885a74b8 @offset=1208 fp=0x00000000885a7c88     kernel: Redzone  00000000885a74b0: bb bb bb bb bb bb bb bb                          ........     kernel: Object   00000000885a74b8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b  kkkkkkkkkkkkkkkk     kernel: Object   00000000885a74c8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b  kkkkkkkkkkkkkkkk     kernel: Object   00000000885a74d8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b  kkkkkkkkkkkkkkkk     kernel: Object   00000000885a74e8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b  kkkkkkkkkkkkkkkk     kernel: Object   00000000885a74f8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b  kkkkkkkkkkkkkkkk     kernel: Object   00000000885a7508: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 68 4b 6b 6b 6b a5  kkkkkkkkkkhKkkk.     kernel: Redzone  00000000885a7518: bb bb bb bb bb bb bb bb                          ........     kernel: Padding  00000000885a756c: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a              ZZZZZZZZZZZZ     kernel: CPU: 0 PID: 387 Comm: systemd-udevd Not tainted 6.8.0-HF #2     kernel: Hardware name: IBM 3931 A01 704 (KVM/Linux)     kernel: Call Trace:     kernel:  [\u003c00000000ca5ab5b8\u003e] dump_stack_lvl+0x90/0x120     kernel:  [\u003c00000000c99d78bc\u003e] check_bytes_and_report+0x114/0x140     kernel:  [\u003c00000000c99d53cc\u003e] check_object+0x334/0x3f8     kernel:  [\u003c00000000c99d820c\u003e] alloc_debug_processing+0xc4/0x1f8     kernel:  [\u003c00000000c99d852e\u003e] get_partial_node.part.0+0x1ee/0x3e0     kernel:  [\u003c00000000c99d94ec\u003e] ___slab_alloc+0xaf4/0x13c8     kernel:  [\u003c00000000c99d9e38\u003e] __slab_alloc.constprop.0+0x78/0xb8     kernel:  [\u003c00000000c99dc8dc\u003e] __kmalloc+0x434/0x590     kernel:  [\u003c00000000c9b4c0ce\u003e] ext4_htree_store_dirent+0x4e/0x1c0     kernel:  [\u003c00000000c9b908a2\u003e] htree_dirblock_to_tree+0x17a/0x3f0     kernel:  ---truncated---","modified":"2026-09-01T20:05:23.533693405Z","published":"2024-05-01T06:15:11.953Z","upstream":["CVE-2024-26957"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26957"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.85-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26957.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26957.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26957.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}