cbcvebase.
CVE-2024-36975
published 2024-06-18

CVE-2024-36975: In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails When asn1_encode_sequence() fails, WARN is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails When asn1_encode_sequence() fails, WARN is not the correct solution. 1. asn1_encode_sequence() is not an internal function (located in lib/asn1_encode.c). 2. Location is known, which makes the stack trace useless. 3. Results a crash if panic_on_warn is set. It is also noteworthy that the use of WARN is undocumented, and it should be avoided unless there is a carefully considered rationale to use it. Replace WARN with pr_err, and print the return value instead, which is only useful piece of information.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 96f650995c70237b061b497c66755e32908f897296f650995c70237b061b497c66755e32908f8972
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 681935009fec3fc22af97ee312d4a24ccf3cf087681935009fec3fc22af97ee312d4a24ccf3cf087
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 1c652e1e10676f942149052d9329b8bf2703529a1c652e1e10676f942149052d9329b8bf2703529a
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < d32c6e09f7c4bec3ebc4941323f0aa6366bc1487d32c6e09f7c4bec3ebc4941323f0aa6366bc1487
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < ff91cc12faf798f573dab2abc976c1d5b1862feaff91cc12faf798f573dab2abc976c1d5b1862fea
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 050bf3c793a07f96bd1e2fd62e1447f731ed733b050bf3c793a07f96bd1e2fd62e1447f731ed733b
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.13 < 5.15.1605.15.160
linuxlinux_kernel>= 5.16 < 6.1.926.1.92
linuxlinux_kernel>= 6.2 < 6.6.326.6.32
linuxlinux_kernel>= 6.7 < 6.8.116.8.11
linuxlinux_kernel>= 6.9 < 6.9.26.9.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.