PT-2024-6985 · Linux+5 · Linux Kernel+5

Published

2024-07-04

·

Updated

2025-02-10

·

CVE-2024-46844

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the use of an uninitialized pointer in the setup one line() function in the Linux kernel. This could potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information. The *error out pointer is not initialized by callers but is still printed in some cases, and the fix involves initializing it in all possible cases in setup one line().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12535
ALT-PU-2024-12541
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-15824
AZL-49797
BDU:2024-08234
CVE-2024-46844
DLA-3912-1
DLA-4008-1
DSA-5782-1
OESA-2024-2216
OESA-2024-2218
OESA-2024-2219
OESA-2024-2220
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu