PT-2024-34107 · Linux+2 · Linux Kernel+2
Parthiban N
·
Published
2024-11-04
·
Updated
2025-02-28
·
CVE-2024-50281
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A NULL pointer dereference issue has been identified in the Linux kernel, specifically in the KEYS: trusted: dcp component. This issue occurs when sealing or unsealing a key blob, as the system does not wait for the AEAD cipher operation to finish before resuming the seal and unseal calls. Under heavy system load, this can result in the buffer being removed from the stack before the cipher operation is complete, leading to NULL pointer dereference errors in the DCP driver during blob creation.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu