PT-2024-29842 · Linux+9 · Linux Kernel+9

Zijun Hu

·

Published

2024-06-12

·

Updated

2025-09-29

·

CVE-2024-42292

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.50
Description The issue is related to an out-of-bounds (OOB) memory access in the zap modalias env() function. This function wrongly calculates the size of the memory block to move, causing an OOB memory access issue if the MODALIAS variable is not the last one within its @env parameter. The problem is fixed by correcting the size calculation for memmove(). There is also a mention of an issue with the irqchip/imx-irqsteer component related to an out-of-bounds read error, which could lead to a denial of service.
Recommendations To resolve the issue, update to Linux kernel version 6.6.50 or later. As a temporary workaround, consider restricting access to the vulnerable zap modalias env() function until a patch is available. Avoid using the MODALIAS variable in the affected @env parameter until the issue is resolved.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8856
ALSA-2024:8870
ALSA-2025_16880
BDU:2025-01451
CESA-2024_8856
CESA-2024_8870
CVE-2024-42292
DLA-3912-1
DLA-4008-1
INFSA-2024_8856
INFSA-2024_8870
INFSA-2025_4341
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2109
OESA-2024-2182
OESA-2024-2183
OESA-2024-2185
OESA-2024-2296
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:8856
RHSA-2024:8870
RHSA-2024_8856
RHSA-2024_8870
RHSA-2025:2270
RHSA-2025:4341
RHSA-2025_4341
RLSA-2024:8856
RLSA-2024:8870
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu