CVE-2024-41079

MEDIUM EPSS 16.9%
Published Jul 29, 20241y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 29, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet: always initialize cqe.result The spec doesn't mandate that the first two double words (aka results) for the command queue entry need to be set to 0 when they are not used (not specified). Though, the target implemention returns 0 for TCP and FC but not for RDMA. Let's make RDMA behave the same and thus explicitly initializing the result field. This prevents leaking any data from the stack.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
16.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel* <6.1.101
linuxlinux_kernel*≥6.2  –  <6.6.42
linuxlinux_kernel*≥6.7  –  <6.9.11
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/0990e8a863645496b9e3f91cfcfd63cd95c80319
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/10967873b80742261527a071954be8b54f0f8e4d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/30d35b24b7957922f81cfdaa66f2e1b1e9b9aed2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c6a2cf8b0764f3ba7d9bff58c8775a6d4476bb29
  • git.kernel.org https://git.kernel.org/stable/c/cd0c1b8e045a8d2785342b385cb2684d9b48e426
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0990e8a863645496b9e3f91cfcfd63cd95c80319
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/10967873b80742261527a071954be8b54f0f8e4d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/30d35b24b7957922f81cfdaa66f2e1b1e9b9aed2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cd0c1b8e045a8d2785342b385cb2684d9b48e426
    Patch