{"schema_version":"1.9.0","id":"CVE-2024-26816","published":"2024-04-10T13:53:49.492Z","modified":"2026-08-12T03:51:15.728955613Z","related":["SUSE-SU-2024:1641-1","SUSE-SU-2024:1642-1","SUSE-SU-2024:1643-1","SUSE-SU-2024:1644-1","SUSE-SU-2024:1645-1","SUSE-SU-2024:1646-1","SUSE-SU-2024:1647-1","SUSE-SU-2024:1650-1","SUSE-SU-2024:1659-1","SUSE-SU-2024:1663-1","SUSE-SU-2024:1870-1","SUSE-SU-2024:2135-1","SUSE-SU-2024:2203-1","SUSE-SU-2024:2973-1","SUSE-SU-2025:20008-1","SUSE-SU-2025:20028-1"],"summary":"x86, relocs: Ignore relocations in .notes section","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86, relocs: Ignore relocations in .notes section\n\nWhen building with CONFIG_XEN_PV=y, .text symbols are emitted into\nthe .notes section so that Xen can find the \"startup_xen\" entry point.\nThis information is used prior to booting the kernel, so relocations\nare not useful. In fact, performing relocations against the .notes\nsection means that the KASLR base is exposed since /sys/kernel/notes\nis world-readable.\n\nTo avoid leaking the KASLR base without breaking unprivileged tools that\nare expecting to read /sys/kernel/notes, skip performing relocations in\nthe .notes section. The values readable in .notes are then identical to\nthose found in System.map.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5ead97c84fa7d63a6a7a2f4e9f18f452bd109045"},{"fixed":"13edb509abc91c72152a11baaf0e7c060a312e03"},{"fixed":"52018aa146e3cf76569a9b1e6e49a2b7c8d4a088"},{"fixed":"a4e7ff1a74274e59a2de9bb57236542aa990d20a"},{"fixed":"c7cff9780297d55d97ad068b68b703cfe53ef9af"},{"fixed":"47635b112a64b7b208224962471e7e42f110e723"},{"fixed":"af2a9f98d884205145fd155304a6955822ccca1c"},{"fixed":"ae7079238f6faf1b94accfccf334e98b46a0c0aa"},{"fixed":"5cb59db49c9c0fccfd33b2209af4f7ae3c6ddf40"},{"fixed":"aaa8736370db1a78f0e8434344a484f9fd20be3b"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26816.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.23"},{"fixed":"4.19.311"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.273"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.214"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.153"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.83"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.23"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.7.11"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.8.0"},{"fixed":"6.8.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26816.json"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/13edb509abc91c72152a11baaf0e7c060a312e03"},{"type":"WEB","url":"https://git.kernel.org/stable/c/47635b112a64b7b208224962471e7e42f110e723"},{"type":"WEB","url":"https://git.kernel.org/stable/c/52018aa146e3cf76569a9b1e6e49a2b7c8d4a088"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5cb59db49c9c0fccfd33b2209af4f7ae3c6ddf40"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a4e7ff1a74274e59a2de9bb57236542aa990d20a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/aaa8736370db1a78f0e8434344a484f9fd20be3b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae7079238f6faf1b94accfccf334e98b46a0c0aa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af2a9f98d884205145fd155304a6955822ccca1c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c7cff9780297d55d97ad068b68b703cfe53ef9af"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26816.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26816"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26816.json"}}