PT-2024-29817 · Linux+9 · Linux Kernel+9

Al Viro

+1

·

Published

2024-03-27

·

Updated

2025-10-03

·

CVE-2024-42265

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.50
Description The issue is related to the Linux kernel, specifically with the do dup2() function, where a misprediction might lead to speculative execution of tofree = fdt->fd[fd]. This is wrong for the same reasons it is wrong in close fd()/file close fd locked(). The solution involves using array index nospec(fd, fdt->max fds) to protect against mispredictions. The vulnerability is associated with incorrect input validation in the fs/file component of the Linux kernel, which could allow an attacker to cause a denial of service.
Recommendations For Linux kernel versions prior to 6.6.50, update to version 6.6.50 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable do dup2() function until a patch is available. Avoid using the fd variable in the affected do dup2() function until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:7000
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-01434
CESA-2024_7000
CVE-2024-42265
DLA-3912-1
DLA-4008-1
INFSA-2024_7000
INFSA-2025_6966
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2076
OESA-2024-2077
OESA-2024-2078
OESA-2024-2079
OESA-2024-2080
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
RHSA-2024:7000
RHSA-2024_7000
RHSA-2025:3215
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3551-1
SUSE-SU-2024:3559-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2024:3566-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3591-1
SUSE-SU-2024:3592-1
SUSE-SU-2025:02849-1
SUSE-SU-2025:02851-1
SUSE-SU-2025:03283-1
SUSE-SU-2025:03310-1
SUSE-SU-2025:03344-1
SUSE-SU-2025:03384-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
SUSE-SU-2025_02849-1
SUSE-SU-2025_03310-1
SUSE-SU-2025_03344-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu