CVE-2024-43865
published 2024-08-21CVE-2024-43865: In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
s390/fpu: Re-add exception handling in load_fpu_state()
With the recent rewrite of the fpu code exception handling for the
lfpc instruction within load_fpu_state() was erroneously removed.
Add it again to prevent that loading invalid floating point register
values cause an unhandled specification exception.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.10.4-1 (forky) | linux 6.10.4-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 8c09871a950a3fe686e0e27fd4193179c5f74f37 < 494b14138201f07343e5488db6360c828fcc8cf6 | 494b14138201f07343e5488db6360c828fcc8cf6 |
| linux | linux | >= 8c09871a950a3fe686e0e27fd4193179c5f74f37 < 4734406c39238cbeafe66f0060084caa3247ff53 | 4734406c39238cbeafe66f0060084caa3247ff53 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.10.4-1 | 6.10.4-1 |
| linux | linux_kernel | >= 0 < 6.10.4-1 | 6.10.4-1 |
| linux | linux_kernel | >= 6.9 < 6.10.4 | 6.10.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: s390/fpu: Re-add exception handling in load_fpu_state()
vendor_redhat·2024-08-20·CVSS 5.5
CVE-2024-43865 [MEDIUM] CWE-703 kernel: s390/fpu: Re-add exception handling in load_fpu_state()
kernel: s390/fpu: Re-add exception handling in load_fpu_state()
In the Linux kernel, the following vulnerability has been resolved:
s390/fpu: Re-add exception handling in load_fpu_state()
With the recent rewrite of the fpu code exception handling for the
lfpc instruction within load_fpu_state() was erroneously removed.
Add it again to prevent that loading invalid floating point register
values cause an unhandled specification exception.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9
Debian
CVE-2024-43865: linux - In the Linux kernel, the following vulnerability has been resolved: s390/fpu: R...
vendor_debian·2024·CVSS 5.5
CVE-2024-43865 [MEDIUM] CVE-2024-43865: linux - In the Linux kernel, the following vulnerability has been resolved: s390/fpu: R...
In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu code exception handling for the lfpc instruction within load_fpu_state() was erroneously removed. Add it again to prevent that loading invalid floating point register values cause an unhandled specification exception.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.10.4-1)
sid: resolved (fixed in 6.10.4-1)
trixie: resolved (fixed in 6.10.4-1)
GHSA
GHSA-453r-h2v5-6vmq: In the Linux kernel, the following vulnerability has been resolved:
s390/fpu: Re-add exception handling in load_fpu_state()
With the recent rewrite
ghsa_unreviewed·2024-08-21
CVE-2024-43865 [MEDIUM] GHSA-453r-h2v5-6vmq: In the Linux kernel, the following vulnerability has been resolved:
s390/fpu: Re-add exception handling in load_fpu_state()
With the recent rewrite
In the Linux kernel, the following vulnerability has been resolved:
s390/fpu: Re-add exception handling in load_fpu_state()
With the recent rewrite of the fpu code exception handling for the
lfpc instruction within load_fpu_state() was erroneously removed.
Add it again to prevent that loading invalid floating point register
values cause an unhandled specification exception.
OSV
CVE-2024-43865: In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of
osv·2024-08-21·CVSS 5.5
CVE-2024-43865 [MEDIUM] CVE-2024-43865: In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of
In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu code exception handling for the lfpc instruction within load_fpu_state() was erroneously removed. Add it again to prevent that loading invalid floating point register values cause an unhandled specification exception.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-21
Published