SB20240603148 - Use of uninitialized resource in Linux kernel lib
Published: June 3, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2024-26849)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the sizeof() function in lib/nlattr.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0ac219c4c3ab253f3981f346903458d20bacab32
- https://git.kernel.org/stable/c/a2ab028151841cd833cb53eb99427e0cc990112d
- https://git.kernel.org/stable/c/7a9d14c63b35f89563c5ecbadf918ad64979712d
- https://git.kernel.org/stable/c/9a0d18853c280f6a0ee99f91619f2442a17a323a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.81
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.21
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7.9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8