PT-2024-35570 · Linux+6 · Linux Kernel+6
Enrico Bravi
+1
·
Published
2024-08-07
·
Updated
2025-10-03
·
CVE-2024-53106
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.65
Description
The issue is related to a buffer overrun in the
ima eventdigest init common function. The ima eventdigest init function calls ima eventdigest init common with HASH ALGO LAST, which is then used to access the hash digest size array, leading to a buffer overrun. A conditional statement is needed to handle this.Recommendations
For Linux kernel versions prior to 6.6.65, update to version 6.6.65 or later to resolve the issue.
As a temporary workaround, consider adding a conditional statement to handle the buffer overrun in the
ima eventdigest init common function until a patch is available.Exploit
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu