#VU90874 Use of uninitialized resource in Linux kernel


Published: 2024-06-03

Vulnerability identifier: #VU90874

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-35915

CWE-ID: CWE-908

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to use of uninitialized resource within the nci_rx_work() function in net/nfc/nci/core.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/11387b2effbb55f58dc2111ef4b4b896f2756240
http://git.kernel.org/stable/c/03fe259649a551d336a7f20919b641ea100e3fff
http://git.kernel.org/stable/c/755e53bbc61bc1aff90eafa64c8c2464fd3dfa3c
http://git.kernel.org/stable/c/ac68d9fa09e410fa3ed20fb721d56aa558695e16
http://git.kernel.org/stable/c/b51ec7fc9f877ef869c01d3ea6f18f6a64e831a7
http://git.kernel.org/stable/c/a946ebee45b09294c8b0b0e77410b763c4d2817a
http://git.kernel.org/stable/c/8948e30de81faee87eeee01ef42a1f6008f5a83a
http://git.kernel.org/stable/c/d24b03535e5eb82e025219c2f632b485409c898f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability