PT-2024-30735 · Linux · Linux Kernel
Antony Antony
·
Published
2024-06-11
·
Updated
2024-08-22
·
CVE-2024-43878
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.10.2
Description
The issue is related to a misconfiguration of the input state slow path in the Linux kernel, which causes a KASAN report error. This error occurs due to a wild-memory-access in the
xfrmi rcv cb function. The vulnerability can potentially lead to a local network compromise.Recommendations
To resolve the issue, update the Linux kernel to version 6.10.2 or later. If updating is not possible, consider applying patches or configuration changes to mitigate the risk of exploitation. However, the exact mitigation measures are not specified in the provided input descriptions.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel