PT-2024-29231 · Linux+2 · Linux Kernel+2

Žilvinas Žaltiena

·

Published

2024-07-09

·

Updated

2024-12-12

·

CVE-2024-41052

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.43
Description The issue is related to the initialization of the count variable in collecting hot-reset devices. This variable is used without initialization, resulting in mistakes in device counting and crashes the userspace if the get hot reset info path is triggered.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.43 or later. As a temporary workaround, consider disabling the vfio/pci module until a patch is available. Restrict access to the get hot reset info path to minimize the risk of exploitation.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03017
CVE-2024-41052
MGASA-2024-0277
MGASA-2024-0278
OESA-2024-2124
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu