PT-2024-30677 · Linux · Linux Kernel
Dan Carpenter
·
Published
2024-07-13
·
Updated
2024-08-22
·
CVE-2024-43815
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, specifically in the crypto: mxs-dcp module. The issue allowed stack memory to leak through the payload field when running AES with a key from one of the hardware's key slots. This was fixed by ensuring the payload field is set to 0 in such cases. The common use case, where the key is supplied from main memory via the descriptor payload, is not affected.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel