Answer in brief
CVE-2024-26789 records a Unknown severity vulnerability in crypto: arm64/neonbs - fix out-of-bounds access on short input. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fc074e130051015e39245a4241956ff122e2f465 <034e2d70b5c7f578200ad09955aeb2aa65d1164a || >=fc074e130051015e39245a4241956ff122e2f465 <1291d278b5574819a7266568ce4c28bce9438705 || >=fc074e130051015e39245a4241956ff122e2f465 <9e8ecd4908b53941ab6f0f51584ab80c6c6606c4 || >=fc074e130051015e39245a4241956ff122e2f465 <1c0cf6d19690141002889d72622b90fc01562ce4 | 034e2d70b5c7f578200ad09955aeb2aa65d1164a, 1291d278b5574819a7266568ce4c28bce9438705, 9e8ecd4908b53941ab6f0f51584ab80c6c6606c4, 1c0cf6d19690141002889d72622b90fc01562ce4 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Apr 4, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: arm64/neonbs - fix out-of-bounds access on short input The bit-sliced implementation of AES-CTR operates on blocks of 128 bytes, and will fall back to the plain NEON version for tail blocks or inputs that are shorter than 128 bytes to begin with. It will call straight into the plain NEON asm helper, which performs all memory accesses in granules of 16 bytes (the size of a NEON register). For this reason, the associated plain NEON glue code will copy inputs shorter than 16 bytes into a temporary buffer, given that this is a rare occurrence and it is not worth the effort to work around this in the asm code. The fallback from the bit-sliced NEON version fails to take this into account, potentially resulting in out-of-bounds accesses. So clone the same workaround, and use a temp buffer for short in/outputs.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-26789 records a Unknown severity vulnerability in crypto: arm64/neonbs - fix out-of-bounds access on short input. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fc074e130051015e39245a4241956ff122e2f465 <034e2d70b5c7f578200ad09955aeb2aa65d1164a || >=fc074e130051015e39245a4241956ff122e2f465 <1291d278b5574819a7266568ce4c28bce9438705 || >=fc074e130051015e39245a4241956ff122e2f465 <9e8ecd4908b53941ab6f0f51584ab80c6c6606c4 || >=fc074e130051015e39245a4241956ff122e2f465 <1c0cf6d19690141002889d72622b90fc01562ce4 | 034e2d70b5c7f578200ad09955aeb2aa65d1164a, 1291d278b5574819a7266568ce4c28bce9438705, 9e8ecd4908b53941ab6f0f51584ab80c6c6606c4, 1c0cf6d19690141002889d72622b90fc01562ce4 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Apr 4, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: arm64/neonbs - fix out-of-bounds access on short input The bit-sliced implementation of AES-CTR operates on blocks of 128 bytes, and will fall back to the plain NEON version for tail blocks or inputs that are shorter than 128 bytes to begin with. It will call straight into the plain NEON asm helper, which performs all memory accesses in granules of 16 bytes (the size of a NEON register). For this reason, the associated plain NEON glue code will copy inputs shorter than 16 bytes into a temporary buffer, given that this is a rare occurrence and it is not worth the effort to work around this in the asm code. The fallback from the bit-sliced NEON version fails to take this into account, potentially resulting in out-of-bounds accesses. So clone the same workaround, and use a temp buffer for short in/outputs.
Quoted source text, attributed separately from HOL analysis.