cbcvebase.
CVE-2024-44947
published 2024-09-02

CVE-2024-44947: In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store()…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.89%
55.8th percentile
In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page contents). So fuse_notify_store() must be more careful to fully initialize page contents (including parts of the page that are beyond end-of-file) before marking the page uptodate. The current code can leave beyond-EOF page contents uninitialized, which makes these uninitialized page contents visible to userspace via mmap(). This is an information leak, but only affects systems which do not enable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the corresponding kernel command line parameter).

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 49934861514d36d0995be8e81bb3312a499d8d9a49934861514d36d0995be8e81bb3312a499d8d9a
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 33168db352c7b56ae18aa55c2cae1a1c5905d30e33168db352c7b56ae18aa55c2cae1a1c5905d30e
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 4690e2171f651e2b415e3941ce17f2f7b813aff64690e2171f651e2b415e3941ce17f2f7b813aff6
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 8c78303eafbf85a728dd84d1750e89240c677dd98c78303eafbf85a728dd84d1750e89240c677dd9
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 831433527773e665bdb635ab5783d0b95d1246f4831433527773e665bdb635ab5783d0b95d1246f4
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < ac42e0f0eb66af966015ee33fd355bc6f5d80cd6ac42e0f0eb66af966015ee33fd355bc6f5d80cd6
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 18a067240817bee8a9360539af5d79a4bf5398a518a067240817bee8a9360539af5d79a4bf5398a5
linuxlinux>= a1d75f258230b75d46aecdf28b2e732413028863 < 3c0da3d163eb32f1f91891efaade027fa9b245b93c0da3d163eb32f1f91891efaade027fa9b245b9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 2.6.36 < 4.19.3214.19.321
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.