CVE-2024-26686: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats
Published Apr 3, 2024
·Updated
fs/proc: dotaskstat: use sig->statslock to gather the threads/children stats
Affected Software
16 affected componentsFixes available
IBM Security Verify Governance<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Software Stack<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Virtual Appliance<=ISVG 10.0.2
IBM Security Verify Governance Identity Manager Container<=ISVG 10.0.2
Linux Linux kernel<6.1.82
Linux Linux kernel>=6.2<6.7.6
Linux Linux kernel=6.8-rc1
Linux Linux kernel=6.8-rc2
Linux Linux kernel=6.8-rc3
redhat/kernel<6.1.82
6.1.82
redhat/kernel<6.7.6
6.7.6
redhat/kernel<6.8
6.8
Microsoft azl3 kernel 6.6.92.2-1
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft azl3 kernel 6.6.82.1-1
Remediation
Event History
Apr 3, 2024
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·10:36 PM
DescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·06:23 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·06:23 AM
Affected Software
Updated
via Microsoft·06:23 AM
SeverityAffected Software
Updated
via Microsoft·06:23 AM
Affected Software
Updated
via Microsoft·06:23 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-26686?
CVE-2024-26686 has been classified as a moderate severity vulnerability in the Linux kernel.
2
How do I fix CVE-2024-26686?
To fix CVE-2024-26686, upgrade your Linux kernel to versions 6.1.82, 6.7.6, or 6.8.
3
What systems are affected by CVE-2024-26686?
CVE-2024-26686 affects various versions of the Linux kernel and specific IBM Security Verify Governance products.
4
What is the impact of CVE-2024-26686?
The impact of CVE-2024-26686 involves potential issues related to thread and child statistics gathering within the Linux kernel.
5
When was CVE-2024-26686 disclosed?
CVE-2024-26686 was disclosed in April 2024 as part of a security update for the Linux kernel.