CVE-2024-26908, initially assigned to missing kasprintf() allocation-failure checks in Linux arch/x86/xen/smp.c, was rejected upstream. The affected code could dereference a NULL pointer during virtual-CPU hotplug under out-of-memory conditions; fixes were nevertheless backported across stable kernel releases from 4.19.311 through 6.8.
Kernel maintainers determined the condition requires vCPU hotplug initiated by a host or guest administrator, rather than exposure to an unprivileged or remote attacker. Red Hat continues to catalog the issue as Moderate, with a 5.5 CVSS v3.1 denial-of-service assessment and RHEL 8 and 9 errata references, but organizations should treat the CVE as rejected rather than an active vulnerability while applying normal kernel maintenance updates.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:5101 with a kernel fix for Red Hat Enterprise Linux 8.
Red Hat issued RHSA-2024:4902 with a kernel fix for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat issued RHSA-2024:6993 with a kernel fix for RHEL 8.8 Extended Update Support.
Red Hat issued RHSA-2024:7002 with a kernel fix for RHEL 8.4 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat issued RHSA-2024:6992 with a kernel fix for RHEL 8.2 Advanced Update Support.
Red Hat issued RHSA-2024:5928 with a kernel fix for Red Hat Enterprise Linux 9.
Greg Kroah-Hartman confirmed that CVE-2024-26908 was rejected. The issue required administrative virtual-CPU hotplug during an out-of-memory condition and was not reachable by unprivileged or remote attackers.
The Linux kernel CVE team assigned CVE-2024-26908 to an x86/Xen smp.c issue where a failed kasprintf() allocation could be used without a NULL check. The upstream fix added validation after the allocation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.