#VU99130 Buffer overflow in Linux kernel - CVE-2024-47731


Vulnerability identifier: #VU99130

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-47731

CWE-ID: CWE-119

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the ali_drw_pmu_isr() function in drivers/perf/alibaba_uncore_drw_pmu.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/24f30b34ff76648d26872dd4eaa002f074225058
https://git.kernel.org/stable/c/3b839d4619042b02eecdfc986484ac6e6be6acbf
https://git.kernel.org/stable/c/062b7176e484678b2c9072d28fbecea47846b274
https://git.kernel.org/stable/c/85702fddba70d2b63f5646793d77de2ad4fc3784
https://git.kernel.org/stable/c/a3dd920977dccc453c550260c4b7605b280b79c3


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability