#VU99150 Resource management error in Linux kernel - CVE-2024-49963


Vulnerability identifier: #VU99150

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-49963

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the bcm2835_mbox_probe() function in drivers/mailbox/bcm2835-mailbox.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
http://git.kernel.org/stable/c/32ee78823dea2d54adaf6e05f86622eba359e091
http://git.kernel.org/stable/c/df293ea78740a41384d648041f38f645700288e1
http://git.kernel.org/stable/c/90320cfc07b7d6e7a58fd8168f6380ec52ff0251
http://git.kernel.org/stable/c/10a58555e0bb5cc4673c8bb73b8afc5fa651f0ac
http://git.kernel.org/stable/c/e65a9af05a0b59ebeba28e5e82265a233db7bc27
http://git.kernel.org/stable/c/dfeb67b2194ecc55ef8065468c5adda3cdf59114
http://git.kernel.org/stable/c/dc09f007caed3b2f6a3b6bd7e13777557ae22bfd


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability