Description A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.
CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Exploitability: 1.8 | Impact: 5.9 Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages Also affects: Enterprise Linux 8.0, 9.0
🔴 Vulnerability Details17 OSV linux-oem-6.5 vulnerabilities ↗ 2024-08-02 ▶ OSV linux-aws-6.5, linux-lowlatency-hwe-6.5, linux-oracle-6.5, linux-starfive-6.5 vulnerabilities ↗ 2024-07-19 ▶ OSV linux-hwe-6.5 vulnerabilities ↗ 2024-07-17 ▶ OSV linux-azure-6.5, linux-gcp-6.5 vulnerabilities ↗ 2024-07-16 ▶ OSV linux, linux-gcp, linux-nvidia-6.5, linux-raspi vulnerabilities ↗ 2024-07-12 ▶ Show 12 more
📋 Vendor Advisories18 Ubuntu Linux kernel vulnerabilities ↗ 2024-08-02 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2024-07-26 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2024-07-19 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2024-07-17 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2024-07-16 ▶ Show 13 more
💬 Community1 Bugzilla CVE-2024-0841 kernel: hugetlbfs: Null pointer dereference in hugetlbfs_fill_super function ↗ 2024-01-02 ▶