PT-2024-9738 · Linux+4 · Linux Kernel+4

Steven Rostedt

·

Published

2024-05-04

·

Updated

2025-09-17

·

CVE-2024-36963

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the way permissions are handled in the tracefs file system. When permissions are generated upon access, they default to the root inode's permission if not set by the user. However, if a remount occurs with specified permissions, only files not changed by the user are updated, while those that were changed are not. This inconsistency can lead to security issues if an administrator forgets about updated file permissions, mistakenly believing that remounting with permissions set would update all files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11473
CVE-2024-36963
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2296
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu