CVE-2024-41052

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Init the count variable in collecting hot-reset devices The count variable is used without initialization, it results in mistakes in the device counting and crashes the userspace if the get hot reset info path is triggered.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Aug 2024, 19:27

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: vfio/pci: inicia la variable de conteo al recopilar dispositivos de reinicio en caliente. La variable de conteo se usa sin inicialización, genera errores en el conteo de dispositivos y bloquea el espacio de usuario si se calienta. Se activa el restablecimiento de la ruta de información.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/5a88a3f67e37e39f933b38ebb4985ba5822e9eca - () https://git.kernel.org/stable/c/5a88a3f67e37e39f933b38ebb4985ba5822e9eca - Patch
References () https://git.kernel.org/stable/c/f44136b9652291ac1fc39ca67c053ac624d0d11b - () https://git.kernel.org/stable/c/f44136b9652291ac1fc39ca67c053ac624d0d11b - Patch
References () https://git.kernel.org/stable/c/f476dffc52ea70745dcabf63288e770e50ac9ab3 - () https://git.kernel.org/stable/c/f476dffc52ea70745dcabf63288e770e50ac9ab3 - Patch
CWE CWE-908
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux

29 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 15:15

Updated : 2024-08-21 19:27


NVD link : CVE-2024-41052

Mitre link : CVE-2024-41052

CVE.ORG link : CVE-2024-41052


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-908

Use of Uninitialized Resource