cbcvebase.
CVE-2024-42094
published 2024-07-29

CVE-2024-42094: In the Linux kernel, the following vulnerability has been resolved: net/iucv: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y…

PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net/iucv: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack is not recommended since it can cause potential stack overflow. Instead, kernel code should always use *cpumask_var API(s) to allocate cpumask var in config-neutral way, leaving allocation strategy to CONFIG_CPUMASK_OFFSTACK. Use *cpumask_var API(s) to address it.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 2b085521be5292016097b5e7ca81b26be3f7098d2b085521be5292016097b5e7ca81b26be3f7098d
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 842afb47d84536fc976fece8fb6c54bea711ad1a842afb47d84536fc976fece8fb6c54bea711ad1a
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 9dadab0db7d904413ea1cdaa13f127da05c31e719dadab0db7d904413ea1cdaa13f127da05c31e71
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 0af718a690acc089aa1bbb95a93df833d864ef530af718a690acc089aa1bbb95a93df833d864ef53
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < d85ca8179a54ff8cf1e1f8c3c9e3799831319baed85ca8179a54ff8cf1e1f8c3c9e3799831319bae
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 724e7965af054079242b8d6f7e50ee226730a756724e7965af054079242b8d6f7e50ee226730a756
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 2d090c7f7be3b26fcb80ac04d08a4a8062b1d9592d090c7f7be3b26fcb80ac04d08a4a8062b1d959
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < be4e1304419c99a164b4c0e101c7c2a756b635b9be4e1304419c99a164b4c0e101c7c2a756b635b9
linuxlinux_kernel< 4.19.3174.19.317
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.376.6.37

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.