CVE-2024-26836

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26836
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26836.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-26836
Downstream
Related
Published
2024-04-17T10:15:09Z
Modified
2025-08-09T19:01:27Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: think-lmi: Fix password opcode ordering for workstations

The Lenovo workstations require the password opcode to be run before the attribute value is changed (if Admin password is enabled).

Tested on some Thinkpads to confirm they are OK with this order too.

References

Affected packages