PT-2025-3603 · Linux+3 · Linux Kernel+3

Catalin Marinas

+1

·

Publicado

2024-12-05

·

Atualizado

2025-09-29

·

CVE-2024-57878

CVSS v3.1

6.1

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel's ptrace system call, specifically the arm64 architecture. The problem arises from the fpmr set() function not initializing the temporary fpmr variable, which can lead to an arbitrary value being written back to target->thread.uw.fpmr when a SETREGSET call with a length of zero is made. This could potentially leak up to 64 bits of memory from the kernel stack. The read is limited to a specific slot on the stack, and there is no write mechanism provided by the issue. The fix involves initializing the temporary value before copying the regset from userspace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2024-17881
BDU:2025-04365
CVE-2024-57878
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Produtos afetados

Alt Linux
Linuxmint
Linux Kernel
Ubuntu