cbcvebase.
CVE-2024-38619
published 2024-06-20

CVE-2024-38619: In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is initialized The member "uzonesize" of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is initialized The member "uzonesize" of struct alauda_info will remain 0 if alauda_init_media() fails, potentially causing divide errors in alauda_read_data() and alauda_write_lba(). - Add a member "media_initialized" to struct alauda_info. - Change a condition in alauda_check_media() to ensure the first initialization. - Add an error check for the return value of alauda_init_media().

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < e0aab7b07a9375337847c9d74a5ec044071e01c8e0aab7b07a9375337847c9d74a5ec044071e01c8
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < 51fe16c058acb22f847e69bc598066ed0bcd5c1551fe16c058acb22f847e69bc598066ed0bcd5c15
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < f68820f1256b21466ff094dd97f243b7e708f9c1f68820f1256b21466ff094dd97f243b7e708f9c1
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < 3eee13ab67f65606faa66e0c3c729e4f514838fd3eee13ab67f65606faa66e0c3c729e4f514838fd
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < e0e2eec76920a133dd49a4fbe4656d83596a1361e0e2eec76920a133dd49a4fbe4656d83596a1361
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < 2cc32639ec347e3365075b130f9953ef16cb13f12cc32639ec347e3365075b130f9953ef16cb13f1
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < 24bff7f714bdff97c2a75a0ff6a368cdf8ad5af424bff7f714bdff97c2a75a0ff6a368cdf8ad5af4
linuxlinux>= e80b0fade09ef1ee67b0898d480d4c588f124d5f < 16637fea001ab3c8df528a8995b3211906165a3016637fea001ab3c8df528a8995b3211906165a30
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 2.6.16 < 4.19.3174.19.317
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.