cbcvebase.
CVE-2024-45014
published 2024-09-11

CVE-2024-45014: In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corruption When physical memory for the…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corruption When physical memory for the kernel image is allocated it does not consider extra memory required for offsetting the image start to match it with the lower 20 bits of KASLR virtual base address. That might lead to kernel access beyond its memory range.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.7-1 (forky)linux 6.10.7-1 (forky)
linuxlinux
linuxlinux>= 693d41f7c938f92d881e6a51525e6c132a186afd < a944cba5d57687b747023c3bc074fcf9c790f7dfa944cba5d57687b747023c3bc074fcf9c790f7df
linuxlinux>= 693d41f7c938f92d881e6a51525e6c132a186afd < d7fd2941ae9a67423d1c7bee985f240e4686634fd7fd2941ae9a67423d1c7bee985f240e4686634f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 6.10 < 6.10.76.10.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.