#VU90874 Use of uninitialized resource in Linux kernel - CVE-2024-35915


Vulnerability identifier: #VU90874

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-35915

CWE-ID: CWE-908

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to use of uninitialized resource within the nci_rx_work() function in net/nfc/nci/core.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/11387b2effbb55f58dc2111ef4b4b896f2756240
https://git.kernel.org/stable/c/03fe259649a551d336a7f20919b641ea100e3fff
https://git.kernel.org/stable/c/755e53bbc61bc1aff90eafa64c8c2464fd3dfa3c
https://git.kernel.org/stable/c/ac68d9fa09e410fa3ed20fb721d56aa558695e16
https://git.kernel.org/stable/c/b51ec7fc9f877ef869c01d3ea6f18f6a64e831a7
https://git.kernel.org/stable/c/a946ebee45b09294c8b0b0e77410b763c4d2817a
https://git.kernel.org/stable/c/8948e30de81faee87eeee01ef42a1f6008f5a83a
https://git.kernel.org/stable/c/d24b03535e5eb82e025219c2f632b485409c898f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability