PT-2025-3668 · Linux+1 · Linux Kernel+1

Published

2024-12-12

·

Updated

2025-01-23

·

CVE-2024-57943

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the exfat component of the Linux kernel, where a new buffer was not zeroed before writing. This could lead to uninitialized data in the page cache being written. The problem is resolved by using folio zero new buffers() to zero the new buffers before ->write end().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

BDU:2025-01840
CVE-2024-57943

Affected Products

Astra Linux
Linux Kernel