PT-2024-26181 · Linux+5 · Linux Kernel+5
Published
2024-05-04
·
Updated
2025-02-03
·
CVE-2024-34777
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.37
Description
The issue arises from the validation of node ids in the
map benchmark ioctl() function, where node possible() may be provided with an invalid argument outside of the [0,MAX NUMNODES-1] range. This leads to a wild-memory-access bug. The NUMA NO NODE is considered a special valid case, meaning benchmarking kthreads won't be bound to a cpuset of a given node. The vulnerability was found by the Linux Verification Center.Recommendations
Update to Linux kernel version 6.6.37 or later to resolve the issue. As a temporary workaround, consider restricting access to the
map benchmark ioctl() function until a patch is available.Exploit
Fix
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu