#VU94119 Use of obsolete function in Linux kernel


Published: 2024-07-11

Vulnerability identifier: #VU94119

Vulnerability risk: Low

CVSSv3.1: 3.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-38620

CWE-ID: CWE-477

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to kernel contains obsolete support for HCI_AMP. A local user can abuse such support, which can lead to potential security issues.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/5af2e235b0d5b797e9531a00c50058319130e156
http://git.kernel.org/stable/c/d3c7b012d912b31ad23b9349c0e499d6dddd48ec
http://git.kernel.org/stable/c/af1d425b6dc67cd67809f835dd7afb6be4d43e03
http://git.kernel.org/stable/c/84a4bb6548a29326564f0e659fb8064503ecc1c7


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability