LiveActive security incident?Get immediate response
CVE Record

CVE-2024-26906: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault()

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() When trying to use copy_from_kernel_nofault() to read vsyscall page through a bpf program, the following oops was reported: BUG: unable to handle page fault for address: ffffffffff600000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 3231067 P4D 3231067 PUD 3233067 PMD 3235067 PTE 0 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 20390 Comm: test_progs ...... 6.7.0+ #58 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ...... RIP: 0010:copy_from_kernel_nofault+0x6f/0x110 ...... Call Trace: <TASK> ? copy_from_kernel_nofault+0x6f/0x110 bpf_probe_read_kernel+0x1d/0x50 bpf_prog_2061065e56845f08_do_probe_read+0x51/0x8d trace_call_bpf+0xc5/0x1c0 perf_call_bpf_enter.isra.0+0x69/0xb0 perf_syscall_enter+0x13e/0x200 syscall_trace_enter+0x188/0x1c0 do_syscall_64+0xb5/0xe0 entry_SYSCALL_64_after_hwframe+0x6e/0x76 </TASK> ...... ---[ end trace 0000000000000000 ]--- The oops is triggered when: 1) A bpf program uses bpf_probe_read_kernel() to read from the vsyscall page and invokes copy_from_kernel_nofault() which in turn calls __get_user_asm(). 2) Because the vsyscall page address is not readable from kernel space, a page fault exception is triggered accordingly. 3) handle_page_fault() considers the vsyscall page address as a user space address instead of a kernel space address. This results in the fix-up setup by bpf not being applied and a page_fault_oops() is invoked due to SMAP. Considering handle_page_fault() has already considered the vsyscall page address as a userspace address, fix the problem by disallowing vsyscall page read for copy_from_kernel_nofault().

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2024-26906 is a Linux kernel stability issue where a BPF read of the legacy vsyscall page can trigger a kernel oops. The source describes a crash path, not remote code execution or data theft. Business impact is mainly availability risk on affected Linux systems that allow such BPF activity.

Executive priority

Prioritize in normal kernel maintenance, with higher urgency for shared or multi-tenant Linux hosts where local BPF access is possible. The current evidence supports availability risk, not confirmed remote compromise. Patch through supported vendor channels and verify deployment.

Technical view

The fault occurs when bpf_probe_read_kernel() reaches copy_from_kernel_nofault() on the vsyscall address. The address is treated as userspace by handle_page_fault(), so the BPF fixup is not applied and page_fault_oops() is reached under SMAP. The kernel fix disallows vsyscall page reads through copy_from_kernel_nofault().

Likely exposure

Exposure is Linux systems running affected kernel branches before the referenced stable fixes, especially hosts where local users, containers, or services can execute BPF/perf tracing paths. Confirm using distribution kernel advisories because vendor kernels backport fixes and the source bundle does not enumerate all package versions.

Exploitation context

No KEV listing or supplied source indicates active exploitation. The described trigger is local BPF-driven behavior that produced a kernel oops in testing. Sources do not claim unauthenticated remote exploitation, privilege escalation, or public weaponization.

Researcher notes

The source evidence is narrowly scoped to x86/mm vsyscall handling and BPF probe reads. Affected version metadata is limited and should be reconciled with downstream kernel backports. Do not assume exploitability beyond the documented kernel oops without additional vendor analysis.

Mitigation direction

  • Apply Linux kernel updates containing the referenced stable commits or distribution backports.
  • Review Debian LTS and Siemens advisories if those platforms are in scope.
  • Restrict unnecessary local BPF/perf tracing access according to existing hardening policy.
  • Prioritize exposed multi-tenant, shared shell, container, and build systems.
  • Track vendor guidance for exact fixed package versions.

Validation and detection

  • Inventory Linux kernel versions across servers, appliances, container hosts, and developer systems.
  • Map versions to vendor advisories and the referenced stable kernel fixes.
  • Check whether untrusted users or workloads can load or trigger BPF programs.
  • Review crash logs for kernel oopses involving copy_from_kernel_nofault or bpf_probe_read_kernel.
  • Confirm patched kernels remain deployed after reboot.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-26906 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
3ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
CISA-ADPCISA ADP Vulnrichment
other:ssvc
siemens-SADPADP container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux75a1a607bb7e6d918be3aca11ec2214a275392f4, 75a1a607bb7e6d918be3aca11ec2214a275392f4, 75a1a607bb7e6d918be3aca11ec2214a275392f4, 75a1a607bb7e6d918be3aca11ec2214a275392f4, 75a1a607bb7e6d918be3aca11ec2214a275392f4, 75a1a607bb7e6d918be3aca11ec2214a275392f4unaffected
LinuxLinux5.5, 0, 5.10.214, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.