Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2024-26697 |
CWE-ID | CWE-200 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Linux kernel Operating systems & Components / Operating system |
Vendor | Linux Foundation |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU91365
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-26697
CWE-ID:
CWE-200 - Exposure of sensitive information to an unauthorized actor
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to information disclosure within the nilfs_prepare_segment_for_recovery(), nilfs_recovery_copy_block() and nilfs_recover_dsync_blocks() functions in fs/nilfs2/recovery.c. A local user can gain access to sensitive information.
MitigationInstall update from vendor's website.
Vulnerable software versionsLinux kernel: 4.19 - 6.8 rc5
CPE2.3https://git.kernel.org/stable/c/5278c3eb6bf5896417572b52adb6be9d26e92f65
https://git.kernel.org/stable/c/a6efe6dbaaf504f5b3f8a5c3f711fe54e7dda0ba
https://git.kernel.org/stable/c/364a66be2abdcd4fd426ffa44d9b8f40aafb3caa
https://git.kernel.org/stable/c/120f7fa2008e3bd8b7680b4ab5df942decf60fd5
https://git.kernel.org/stable/c/9c9c68d64fd3284f7097ed6ae057c8441f39fcd3
https://git.kernel.org/stable/c/2e1480538ef60bfee5473dfe02b1ecbaf1a4aa0d
https://git.kernel.org/stable/c/2000016bab499074e6248ea85aeea7dd762355d9
https://git.kernel.org/stable/c/67b8bcbaed4777871bb0dcc888fb02a614a98ab1
https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.307
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.210
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.149
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.269
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.79
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.18
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7.6
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.