cbcvebase.
CVE-2024-42292
published 2024-08-17

CVE-2024-42292: In the Linux kernel, the following vulnerability has been resolved: kobject_uevent: Fix OOB access within zap_modalias_env() zap_modalias_env() wrongly…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: kobject_uevent: Fix OOB access within zap_modalias_env() zap_modalias_env() wrongly calculates size of memory block to move, so will cause OOB memory access issue if variable MODALIAS is not the last one within its @env parameter, fixed by correcting size to memmove.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < 81a15d28f32af01493ae8c5457e0d55314a4167d81a15d28f32af01493ae8c5457e0d55314a4167d
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < b59a5e86a3934f1b6a5bd1368902dbc79bdecc90b59a5e86a3934f1b6a5bd1368902dbc79bdecc90
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < 648d5490460d38436640da0812bf7f6351c150d2648d5490460d38436640da0812bf7f6351c150d2
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < c5ee8adc8d98a49703320d13878ba2b923b142f5c5ee8adc8d98a49703320d13878ba2b923b142f5
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < 68d63ace80b76395e7935687ecdb86421adc216868d63ace80b76395e7935687ecdb86421adc2168
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < 57fe01d3d04276875c7e3a6dc763517fc05b876257fe01d3d04276875c7e3a6dc763517fc05b8762
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < d4663536754defff75ff1eca0aaebc41da165a8dd4663536754defff75ff1eca0aaebc41da165a8d
linuxlinux>= 9b3fa47d4a76b1d606a396455f9bbeee083ef008 < dd6e9894b451e7c85cceb8e9dc5432679a70e7dcdd6e9894b451e7c85cceb8e9dc5432679a70e7dc
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.15.1 < 4.19.3204.19.320
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.446.6.44

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.