cbcvebase.
CVE-2024-44994
published 2024-09-04

CVE-2024-44994: In the Linux kernel, the following vulnerability has been resolved: iommu: Restore lost return in iommu_report_device_fault() When iommu_report_device_fault…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: iommu: Restore lost return in iommu_report_device_fault() When iommu_report_device_fault gets called with a partial fault it is supposed to collect the fault into the group and then return. Instead the return was accidently deleted which results in trying to process the fault and an eventual crash. Deleting the return was a typo, put it back.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.7-1 (forky)linux 6.10.7-1 (forky)
linuxlinux
linuxlinux>= 3dfa64aecbafc288216b2790438d395add192c30 < cc6bc2ab1663ec9353636416af22452b078510e9cc6bc2ab1663ec9353636416af22452b078510e9
linuxlinux>= 3dfa64aecbafc288216b2790438d395add192c30 < fca5b78511e98bdff2cdd55c172b23200a7b3404fca5b78511e98bdff2cdd55c172b23200a7b3404
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 6.9 < 6.10.76.10.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.