#VU91363 Information disclosure in Linux kernel


Published: 2024-06-08

Vulnerability identifier: #VU91363

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-26901

CWE-ID: CWE-200

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to information disclosure within the do_sys_name_to_handle() function in fs/fhandle.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/4bac28f441e3cc9d3f1a84c8d023228a68d8a7c1
http://git.kernel.org/stable/c/772a7def9868091da3bcb0d6c6ff9f0c03d7fa8b
http://git.kernel.org/stable/c/cde76b3af247f615447bcfecf610bb76c3529126
http://git.kernel.org/stable/c/423b6bdf19bbc5e1f7e7461045099917378f7e71
http://git.kernel.org/stable/c/e6450d5e46a737a008b4885aa223486113bf0ad6
http://git.kernel.org/stable/c/c1362eae861db28b1608b9dc23e49634fe87b63b
http://git.kernel.org/stable/c/cba138f1ef37ec6f961baeab62f312dedc7cf730
http://git.kernel.org/stable/c/bf9ec1b24ab4e94345aa1c60811dd329f069c38b
http://git.kernel.org/stable/c/3948abaa4e2be938ccdfc289385a27342fb13d43


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability