PT-2024-7291 · Linux+3 · Linux Kernel+3

Published

2024-02-10

·

Updated

2024-10-22

·

CVE-2024-26711

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to insufficient input validation in the ad4130 component of the Linux kernel. This can cause problems when trying to expose the internal clock on the CLK pin due to the clk init data struct not having all its members initialized. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations: As a temporary workaround, consider initializing the clk init data struct to zero to prevent issues with exposing the internal clock on the CLK pin. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08645
CVE-2024-26711
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Ubuntu