PT-2024-30735 · Linux · Linux Kernel

Antony Antony

·

Published

2024-06-11

·

Updated

2024-08-22

·

CVE-2024-43878

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.10.2
Description The issue is related to a misconfiguration of the input state slow path in the Linux kernel, which causes a KASAN report error. This error occurs due to a wild-memory-access in the xfrmi rcv cb function. The vulnerability can potentially lead to a local network compromise.
Recommendations To resolve the issue, update the Linux kernel to version 6.10.2 or later. If updating is not possible, consider applying patches or configuration changes to mitigate the risk of exploitation. However, the exact mitigation measures are not specified in the provided input descriptions.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-03542
CVE-2024-43878

Affected Products

Linux Kernel