#VU92361 Improper locking in Linux kernel


Published: 2024-06-20

Vulnerability identifier: #VU92361

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-38597

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the gem_interrupt() and gem_init_one() functions in drivers/net/ethernet/sun/sungem.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/e22b23f5888a065d084e87db1eec639c445e677f
http://git.kernel.org/stable/c/fbeeb55dbb33d562149c57e794f06b7414e44289
http://git.kernel.org/stable/c/476adb3bbbd7886e8251d3b9ce2d3c3e680f35d6
http://git.kernel.org/stable/c/5de5aeb98f9a000adb0db184e32765e4815d860b
http://git.kernel.org/stable/c/faf94f1eb8a34b2c31b2042051ef36f63420ecce
http://git.kernel.org/stable/c/6400d205fbbcbcf9b8510157e1f379c1d7e2e937
http://git.kernel.org/stable/c/ac0a230f719b02432d8c7eba7615ebd691da86f4


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability