CVE-2024-36020Use of Uninitialized Resource in Linux

Severity
5.5MEDIUMNVD
OSV7.8OSV7.0OSV6.8
EPSS
0.0%
top 97.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateNov 25

Description

In the Linux kernel, the following vulnerability has been resolved: i40e: fix vf may be used uninitialized in this function warning To fix the regression introduced by commit 52424f974bc5, which causes servers hang in very hard to reproduce conditions with resets races. Using two sources for the information is the root cause. In this function before the fix bumping v didn't mean bumping vf pointer. But the code used this variables interchangeably, so stale vf could point to different/not inten

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel4.19.2644.19.312+9
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-189.209+3
CVEListV5linux/linux76ed715836c6994bac29d9638e9314e6e3b08651cc9cd02dd9e8b7764ea9effb24f4f1dd73d1b23d+9
debiandebian/linux< linux 6.1.85-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

21
OSV
linux-oracle vulnerabilities2024-11-25
OSV
linux-azure vulnerabilities2024-11-20
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2024-11-19
OSV
linux-xilinx-zynqmp vulnerabilities2024-09-18
OSV
linux-gcp-5.15 vulnerabilities2024-07-30

📋Vendor Advisories

22
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-11-25
Ubuntu
Linux kernel (Azure) vulnerabilities2024-11-20
Ubuntu
Linux kernel vulnerabilities2024-11-19
Ubuntu
Linux kernel vulnerabilities2024-09-18
Ubuntu
Linux kernel vulnerabilities2024-07-30

💬Community

1
Bugzilla
CVE-2024-36020 kernel: i40e: fix vf may be used uninitialized in this function warning2024-06-03