PT-2024-33817 · Linux+8 · Linux Kernel+8
Will Deacon
·
Published
2024-10-21
·
Updated
2025-09-29
·
CVE-2024-49975
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
A kernel info leak has been resolved in the Linux kernel. The issue occurs because the
xol add vma() function maps an uninitialized page allocated by create xol area() into userspace, making this memory readable on some architectures, such as x86, even without the necessary permissions. This allows a debugger to read the memory, potentially exposing sensitive information.Recommendations:
For versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider restricting access to the
xol add vma() function and the create xol area() function until a patch is available. Additionally, ensure that the VM READ and VM EXEC permissions are properly set to minimize the risk of exploitation.Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu