#VU105419 Resource management error in Linux kernel - CVE-2024-58054


Vulnerability identifier: #VU105419

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-58054

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the max96712_probe() function in drivers/staging/media/max96712/max96712.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/1556b9149b81cc549c13f5e56e81e89404d8a666
https://git.kernel.org/stable/c/278a98f6d8a7bbe1110433b057333536e4490edf
https://git.kernel.org/stable/c/3311c5395e7322298b659b8addc704b39fb3a59c
https://git.kernel.org/stable/c/dfde3d63afbaae664c4d36e53cfb4045d5374561
https://git.kernel.org/stable/c/ee1b5046d5cd892a0754ab982aeaaad3702083a5


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability