cbcvebase.
CVE-2024-42093
published 2024-07-29

CVE-2024-42093: In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y…

PriorityP337high7.3CVSS 3.1
AVLACLPRLUINSUCLIHAH
EPSS
0.22%
13.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack is not recommended since it can cause potential stack overflow. Instead, kernel code should always use *cpumask_var API(s) to allocate cpumask var in config-neutral way, leaving allocation strategy to CONFIG_CPUMASK_OFFSTACK. Use *cpumask_var API(s) to address it.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < b2262b3be27cee334a2fa175ae3afb53f38fb0b1b2262b3be27cee334a2fa175ae3afb53f38fb0b1
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < 763896ab62a672d728f5eb10ac90d98c607a8509763896ab62a672d728f5eb10ac90d98c607a8509
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < a55afc0f5f20ba30970aaf7271929dc00eee5e7da55afc0f5f20ba30970aaf7271929dc00eee5e7d
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < 48147337d7efdea6ad6e49f5b8eb894b95868ef048147337d7efdea6ad6e49f5b8eb894b95868ef0
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < 69f49527aea12c23b78fb3d0a421950bf44fb4e269f49527aea12c23b78fb3d0a421950bf44fb4e2
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < 5e4f25091e6d06e99a23f724c839a58a8776a5275e4f25091e6d06e99a23f724c839a58a8776a527
linuxlinux>= 93ddf0b211a0a0367d01c9587169c16ed77b4b98 < d33fe1714a44ff540629b149d8fab4ac6967585cd33fe1714a44ff540629b149d8fab4ac6967585c
linuxlinux_kernel< 5.4.2795.4.279
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.376.6.37
linuxlinux_kernel>= 6.7 < 6.9.86.9.8
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.