cbcvebase.
CVE-2024-42158
published 2024-07-30

CVE-2024-42158: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and…

PriorityP414medium4.1CVSS 3.1
AVLACHPRHUINSUCHINAN
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle: WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1770)

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.9-1 (forky)linux 6.9.9-1 (forky)
linuxlinux
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 62151a0acde90823bdfa991d598c85cf4b1d387d62151a0acde90823bdfa991d598c85cf4b1d387d
linuxlinux>= e80d4af0a320972aac58e2004d0ba4e44ef4c5c7 < 22e6824622e8a8889df0f8fc4ed5aea0e702a69422e6824622e8a8889df0f8fc4ed5aea0e702a694
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 4.11 < 6.9.96.9.9

CVSS provenance

nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.