PT-2024-10453 · Linux+5 · Linux Kernel+5

Published

2024-07-30

·

Updated

2025-02-03

·

CVE-2024-42106

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.43
Description The vulnerability is related to the inet diag component of the Linux kernel, which is used for socket diagnostics. The issue occurs due to the use of an uninitialized resource, specifically the pad field in the struct inet diag req v2. This field is used for the underlying protocol in raw sockets and corresponds to the sdiag raw protocol field in struct inet diag req raw. When the raw lookup() function accesses the sdiag raw protocol field, it may cause an uninit-value access, leading to a potential denial-of-service. The vulnerability can be exploited by an attacker to cause a crash or potentially execute arbitrary code.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.43 or later. This update includes the necessary fixes to initialize the pad field in the struct inet diag req v2, preventing the uninit-value access and potential denial-of-service. Additionally, ensure that any dependent packages, such as kmod-virtualbox and kmod-xtables-addons, are also updated to be compatible with the new kernel version.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00993
CVE-2024-42106
DLA-4008-1
DSA-5747-1
MGASA-2024-0277
MGASA-2024-0278
OESA-2024-1961
OESA-2024-1962
OESA-2024-1963
OESA-2024-1964
OESA-2025-1078
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3189-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7003-1
USN-7003-2
USN-7003-3
USN-7003-4
USN-7003-5
USN-7006-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7009-1
USN-7009-2
USN-7019-1
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu