Input validation error in Linux kernel - CVE-2024-58075
Published: March 6, 2025 / Updated: May 11, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the tegra_sha_digest() function in drivers/crypto/tegra/tegra-se-hash.c, within the tegra_cmac_digest() function in drivers/crypto/tegra/tegra-se-aes.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-lowlatency (Ubuntu package)
How to mitigate CVE-2024-58075
linux (Ubuntu package) - addressed in versions 6.11.0-26.26, 6.11.0-26.26~24.04.1, 6.11.0-1010.10, 6.11.0-1013.13, 6.11.0-1015.15, 6.11.0-1015.15~24.04.1, 6.11.0-1022.22
linux-aws (Ubuntu package) - update to 6.11.0-1014.15
linux-lowlatency (Ubuntu package) - addressed in versions 6.11.0-1014.15, 6.11.0-1014.15~24.04.1, 6.11.0-1016.17