PT-2024-32225 · Linux+5 · Linux Kernel+5

Ivan Orlov

·

Published

2024-08-15

·

Updated

2026-05-26

·

CVE-2024-46823

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the 'device name' array in the 'overflow allocation test' function scope. This array is being used as a driver name when calling 'kunit driver create' from 'kunit device register', which produces a kernel panic with KASAN enabled. The variable is used in one place only, and the fix involves removing it and passing the device name into 'kunit device register' directly as an ascii string.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
AZL-53307
AZL-53346
BDU:2025-05975
CVE-2024-46823
DLA-4193-1
DSA-5907-1
ECHO-B27B-89A7-7FD1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu