cbcvebase.
CVE-2024-42157
published 2024-07-30

CVE-2024-42157: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe sensitive data on failure Wipe sensitive data from stack also if the…

PriorityP416medium4.1CVSS 3.1
AVLACHPRHUINSUCHINAN
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe sensitive data on failure Wipe sensitive data from stack also if the copy_to_user() fails.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 6e2e374403bf73140d0efc9541cb1b3bea55ac026e2e374403bf73140d0efc9541cb1b3bea55ac02
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < b5eb9176ebd4697bc248bf8d145e66d782cf5250b5eb9176ebd4697bc248bf8d145e66d782cf5250
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 93c034c4314bc4c4450a3869cd5da298502346ad93c034c4314bc4c4450a3869cd5da298502346ad
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 4889f117755b2f18c23045a0f57977f3ec1305814889f117755b2f18c23045a0f57977f3ec130581
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < c51795885c801b6b7e976717e0d6d45b1e5be0f0c51795885c801b6b7e976717e0d6d45b1e5be0f0
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 90a01aefb84b09ccb6024d75d85bb8f620bd348790a01aefb84b09ccb6024d75d85bb8f620bd3487
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < c44a2151e5d21c66b070a056c26471f30719b575c44a2151e5d21c66b070a056c26471f30719b575
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 1d8c270de5eb74245d72325d285894a577a945d91d8c270de5eb74245d72325d285894a577a945d9
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 4.11 < 4.19.3184.19.318
linuxlinux_kernel>= 4.20 < 5.4.2805.4.280
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 5.5 < 5.10.2225.10.222
linuxlinux_kernel>= 6.2 < 6.6.396.6.39

CVSS provenance

nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.1MEDIUM
vendor_msrc4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.