PT-2024-27194 · Linux+6 · Linux Kernel+6
Kent Gibson
·
Published
2024-05-10
·
Updated
2026-05-26
·
CVE-2024-36898
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue arises when a line is requested with debounce and subsequently reconfigured to enable edge detection, resulting in the allocation of the kfifo to contain edge events being overlooked. This leads to events being written to and read from an uninitialised kfifo, with read events being returned to userspace. The problem is resolved by initialising the kfifo in the case where the software debounce is already active.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu