PT-2024-20647 · Openeuler · Openeuler Kernel
Caoyh23@M.Fudan.Edu.Cn
+1
·
Published
2024-04-03
·
Updated
2024-04-15
·
CVE-2024-24891
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
openEuler kernel versions 4.19.90-2109.1.0.0108 through 4.19.90-2403.4.0.0244
Description
The issue allows exposure of sensitive information to an unauthorized actor, resulting in Resource Leak Exposure. This vulnerability is associated with program files at https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C.
Recommendations
Upgrade the kernel to a patched version as soon as possible.
Audit systems for signs of exploit attempts or unauthorized access.
Notify stakeholders of the remediation plan.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openeuler Kernel