#VU99042 Input validation error in Linux kernel - CVE-2024-49948


Vulnerability identifier: #VU99042

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-49948

CWE-ID: CWE-20

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the qdisc_pkt_len_init() function in net/core/dev.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
http://git.kernel.org/stable/c/566a931a1436d0e0ad13708ea55479b95426213c
http://git.kernel.org/stable/c/2415f465730e48b6e38da1c7c097317bf5dd2d20
http://git.kernel.org/stable/c/27a8fabc54d2f960d47bdfbebf2bdc6e8a92a4c4
http://git.kernel.org/stable/c/9b0ee571d20a238a22722126abdfde61f1b2bdd0
http://git.kernel.org/stable/c/ff1c3cadcf405ab37dd91418a62a7acecf3bc5e2
http://git.kernel.org/stable/c/1eebe602a8d8264a12e35e39d0645fa88dbbacdd
http://git.kernel.org/stable/c/ab9a9a9e9647392a19e7a885b08000e89c86b535


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability