Information disclosure in Linux kernel fs



Published: 2024-06-08
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-26901
CWE-ID CWE-200
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU91363

Risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-26901

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to information disclosure within the do_sys_name_to_handle() function in fs/fhandle.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions

External links

http://git.kernel.org/stable/c/4bac28f441e3cc9d3f1a84c8d023228a68d8a7c1
http://git.kernel.org/stable/c/772a7def9868091da3bcb0d6c6ff9f0c03d7fa8b
http://git.kernel.org/stable/c/cde76b3af247f615447bcfecf610bb76c3529126
http://git.kernel.org/stable/c/423b6bdf19bbc5e1f7e7461045099917378f7e71
http://git.kernel.org/stable/c/e6450d5e46a737a008b4885aa223486113bf0ad6
http://git.kernel.org/stable/c/c1362eae861db28b1608b9dc23e49634fe87b63b
http://git.kernel.org/stable/c/cba138f1ef37ec6f961baeab62f312dedc7cf730
http://git.kernel.org/stable/c/bf9ec1b24ab4e94345aa1c60811dd329f069c38b
http://git.kernel.org/stable/c/3948abaa4e2be938ccdfc289385a27342fb13d43


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###