PT-2024-29251 · Linux+7 · Linux Kernel+7
Published
2024-06-12
·
Updated
2026-05-26
·
CVE-2024-41079
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the nvmet component in the Linux kernel, where the
cqe.result field is not initialized properly. According to the specification, the first two double words (aka results) for the command queue entry do not need to be set to 0 when they are not used. However, the target implementation returns 0 for TCP and FC but not for RDMA. To fix this, the cqe.result field is explicitly initialized to prevent leaking any data from the stack.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu