cbcvebase.
CVE-2024-46865
published 2024-09-27

CVE-2024-46865: In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux>= 1df42be305fe478ded1ee0c1d775f4ece713483b < 7ae890ee19479eeeb87724cca8430b5cb3660c747ae890ee19479eeeb87724cca8430b5cb3660c74
linuxlinux>= 231c235d2f7a66f018f172e26ffd47c363f244ef < 392f6a97fcbecc64f0c00058b2db5bb0e4b8cc3e392f6a97fcbecc64f0c00058b2db5bb0e4b8cc3e
linuxlinux>= 4494bccb52ffda22ce5a1163a776d970e6229e08 < 16ff0895283058b0f96d4fe277aa25ee096f0ea816ff0895283058b0f96d4fe277aa25ee096f0ea8
linuxlinux>= 5.10.226 < 5.10.2275.10.227
linuxlinux>= 5.15.167 < 5.15.1685.15.168
linuxlinux>= 6.1.110 < 6.1.1116.1.111
linuxlinux>= 6.10.10 < 6.10.116.10.11
linuxlinux>= 6.6.51 < 6.6.526.6.52
linuxlinux>= 7e4196935069947d8b70b09c1660b67b067e75cb < 4c8002277167125078e6b9b90137bdf443ebaa084c8002277167125078e6b9b90137bdf443ebaa08
linuxlinux>= c46cd6aaca81040deaea3500ba75126963294bd9 < aca06c617c83295f0caa486ad608fbef7bdc11e8aca06c617c83295f0caa486ad608fbef7bdc11e8
linuxlinux>= d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3 < 5d537b8d900514509622ce92330b70d2e581d4095d537b8d900514509622ce92330b70d2e581d409
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.