PT-2024-5781 · Linux+10 · Linux Kernel+10

Syzbot

·

Published

2024-04-17

·

Updated

2025-09-29

·

CVE-2024-26901

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A kernel information leak vulnerability was identified in the do sys name to handle() function. The vulnerability allows for the disclosure of sensitive information. The issue arises from the use of kmalloc() instead of kzalloc(), leading to uninitialized memory being accessed. The vulnerability was detected by syzbot, which issued a report detailing the issue. The report indicates that the vulnerability occurs in the instrument copy to user function, specifically in the copy to user and copy to user functions. The vulnerability can be exploited to cause a denial of service.
Recommendations To resolve the issue, use kzalloc() instead of kmalloc() in the do sys name to handle() function to ensure that the allocated memory is initialized. As a temporary workaround, consider disabling the do sys name to handle() function until a patch is available. However, since the provided information suggests that the issue is resolved by using kzalloc(), the primary recommendation is to apply this fix. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but using kzalloc() as suggested should mitigate the issue.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3618
ALSA-2024:3627
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-14046
ALT-PU-2024-7511
AZL-40082
BDU:2024-06496
CESA-2024_3618
CESA-2024_3627
CVE-2024-26901
DLA-3840-1
DLA-3842-1
DSA-5681-1
INFSA-2024_3618
INFSA-2024_3627
INFSA-2024_9315
OESA-2024-1647
OESA-2024-1648
OESA-2024-1649
OESA-2024-1650
OESA-2024-1651
OESA-2024-1652
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
RHSA-2024:3618
RHSA-2024:3627
RHSA-2024:9315
RHSA-2024_3618
RHSA-2024_3627
RHSA-2024_9315
RHSA-2025:8248
RLSA-2024:3618
RLSA-2024:3627
SUSE-SU-2024:1643-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6871-1
USN-6878-1
USN-6892-1
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6919-1
USN-6926-1
USN-6926-2
USN-6926-3
USN-6938-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu