PT-2024-29231 · Linux+2 · Linux Kernel+2
Žilvinas Žaltiena
·
Published
2024-07-09
·
Updated
2024-12-12
·
CVE-2024-41052
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.43
Description
The issue is related to the initialization of the count variable in collecting hot-reset devices. This variable is used without initialization, resulting in mistakes in device counting and crashes the userspace if the get hot reset info path is triggered.
Recommendations
To resolve the issue, update the Linux kernel to version 6.6.43 or later.
As a temporary workaround, consider disabling the vfio/pci module until a patch is available.
Restrict access to the get hot reset info path to minimize the risk of exploitation.
Exploit
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu