CVE-2024-0340Sensitive Information Exposure in Kernel

Severity
5.5MEDIUMNVD
OSV7.8OSV7.5
EPSS
0.0%
top 99.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMar 27

Description

A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This issue can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Patches

🔴Vulnerability Details

14
OSV
linux-intel-iotg, linux-intel-iotg-5.15 vulnerabilities2024-03-27
OSV
linux-azure, linux-azure-5.4 vulnerabilities2024-03-25
OSV
linux-aws, linux-aws-5.15 vulnerabilities2024-03-20
OSV
linux-kvm vulnerabilities2024-03-20
OSV
linux-oracle, linux-oracle-5.15 vulnerabilities2024-03-19

📋Vendor Advisories

13
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-03-27
Ubuntu
Linux kernel (Azure) vulnerabilities2024-03-25
Ubuntu
Linux kernel (AWS) vulnerabilities2024-03-20
Ubuntu
Linux kernel (KVM) vulnerabilities2024-03-20
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-03-19

💬Community

1
Bugzilla
CVE-2024-0340 kernel: Information disclosure in vhost/vhost.c:vhost_new_msg()2024-01-09