#VU102960 Use of uninitialized resource in Linux kernel - CVE-2024-57802


Vulnerability identifier: #VU102960

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-57802

CWE-ID: CWE-908

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to use of uninitialized resource within the nr_route_frame() function in net/netrom/nr_route.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/3ba7f80d98d4965349cfcd258dd78418496c1625
https://git.kernel.org/stable/c/64e9f54a14f2887be8634fb85cd2f13bec18a184
https://git.kernel.org/stable/c/769e36c2119a51070faf58819c58274f57a088db
https://git.kernel.org/stable/c/78a110332ae268d0b005247c3b9a7d703b875c49
https://git.kernel.org/stable/c/a4fd163aed2edd967a244499754dec991d8b4c7d
https://git.kernel.org/stable/c/cf6befa7c569787f53440274bbed1405fc07738d
https://git.kernel.org/stable/c/f647d72245aadce30618f4c8fd3803904418dbec


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability