cbcvebase.
CVE-2024-42312
published 2024-08-17

CVE-2024-42312: In the Linux kernel, the following vulnerability has been resolved: sysctl: always initialize i_uid/i_gid Always initialize i_uid/i_gid inside the sysfs core…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.1th percentile
In the Linux kernel, the following vulnerability has been resolved: sysctl: always initialize i_uid/i_gid Always initialize i_uid/i_gid inside the sysfs core so set_ownership() can safely skip setting them. Commit 5ec27ec735ba ("fs/proc/proc_sysctl.c: fix the default values of i_uid/i_gid on /proc/sys inodes.") added defaults for i_uid/i_gid when set_ownership() was not implemented. It also missed adjusting net_ctl_set_ownership() to use the same default values in case the computation of a better value failed.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.135 < 4.154.15
linuxlinux>= 4.19.61 < 4.204.20
linuxlinux>= 4.9.187 < 4.104.10
linuxlinux>= 5.1.20 < 5.25.2
linuxlinux>= 5.2.3 < 5.35.3
linuxlinux>= 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf < b2591c89a6e2858796111138c38fcb6851aa1955b2591c89a6e2858796111138c38fcb6851aa1955
linuxlinux>= 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf < 34a86adea1f2b3c3f9d864c8cce09dca644601ab34a86adea1f2b3c3f9d864c8cce09dca644601ab
linuxlinux>= 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf < 1deae34db9f4f8e0e03f891be2e2e15c15c8ac051deae34db9f4f8e0e03f891be2e2e15c15c8ac05
linuxlinux>= 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf < ffde3af4b29bf97d62d82e1d45275587e10a991affde3af4b29bf97d62d82e1d45275587e10a991a
linuxlinux>= 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf < c7e2f43d182f5dde473389dbb39f16c9f0d64536c7e2f43d182f5dde473389dbb39f16c9f0d64536
linuxlinux>= 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf < 98ca62ba9e2be5863c7d069f84f7166b45a5b2f498ca62ba9e2be5863c7d069f84f7166b45a5b2f4
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.