#VU96114 Out-of-bounds read in Linux kernel - CVE-2024-42292
Published: August 19, 2024 / Updated: May 12, 2025
Vulnerability identifier: #VU96114
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-42292
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the zap_modalias_env() function in lib/kobject_uevent.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
External links
- https://git.kernel.org/stable/c/68d63ace80b76395e7935687ecdb86421adc2168
- https://git.kernel.org/stable/c/57fe01d3d04276875c7e3a6dc763517fc05b8762
- https://git.kernel.org/stable/c/d4663536754defff75ff1eca0aaebc41da165a8d
- https://git.kernel.org/stable/c/dd6e9894b451e7c85cceb8e9dc5432679a70e7dc
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.320
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.224
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.165
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.282
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.103
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.44