PT-2024-27194 · Linux+6 · Linux Kernel+6

Kent Gibson

·

Published

2024-05-10

·

Updated

2026-05-26

·

CVE-2024-36898

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises when a line is requested with debounce and subsequently reconfigured to enable edge detection, resulting in the allocation of the kfifo to contain edge events being overlooked. This leads to events being written to and read from an uninitialised kfifo, with read events being returned to userspace. The problem is resolved by initialising the kfifo in the case where the software debounce is already active.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

AZL-67503
BDU:2025-08074
CVE-2024-36898
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1706
OESA-2024-1707
OESA-2024-1766
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0577-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu