PT-2024-7062 · Linux+7 · Linux Kernel+7
Jann Horn
·
Published
2024-08-18
·
Updated
2025-09-29
·
CVE-2024-44947
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.50
Description
The issue is related to the
fuse notify store() function in the Linux kernel, which does not enable page zeroing. This can lead to an information leak, as uninitialized page contents beyond the end-of-file can be visible to userspace via mmap(). The vulnerability only affects systems that do not enable init-on-alloc.Recommendations
To resolve the issue, update the Linux kernel to version 6.6.50 or later. As a temporary workaround, consider enabling init-on-alloc via
CONFIG INIT ON ALLOC DEFAULT ON=y or the corresponding kernel command line parameter to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu