CVE-2024-26714
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-26714 affects the Linux kernel's interconnect subsystem, specifically the Qualcomm SC8180x driver. The vulnerability was discovered and disclosed in April 2024, relating to a hardware connection issue where the CO0 BCM (Bus Clock Manager) component needs to maintain constant operation to prevent system hangs (Kernel Git).

Technical details

The vulnerability exists in the interconnect/qcom/sc8180x.c driver where the CO0 BCM was not properly marked as keepalive. When the BCM is not kept active, it causes the UFS controller to lose its connection to the rest of the SoC (System on Chip), resulting in platform hangs and extensive system log messages (Kernel Git).

Impact

When exploited, this vulnerability can cause the platform to hang and generate excessive log messages. The issue specifically affects the UFS controller's connectivity to the SoC, potentially disrupting storage operations and system stability (Kernel Git).

Exploitability

The vulnerability requires no special privileges to trigger, as it's a design issue in the hardware interconnect management. The issue manifests when the CO0 BCM is allowed to become inactive, which can occur during normal system operation (Kernel Git).

Mitigation and workarounds

The issue has been fixed by marking the CO0 BCM as keepalive in the driver code. The fix was implemented through a patch that adds the keepalive flag to the bcm_co0 structure. This ensures the BCM remains active at all times, preventing the connection loss and subsequent system hangs (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68422NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68399NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68398NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68376NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68374NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management