cbcvebase.
CVE-2024-50076
published 2024-10-29

CVE-2024-50076: In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory…

PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.59%
45.0th percentile
In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the implementation of vc->vc_sw->con_font_get. This may cause info-leak, so to prevent this, it is safest to modify it to initialize the allocated memory space to 0, and it generally does not affect the overall performance of the system.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < efc67cee700b89ffbdb74a0603a083ec1290ae31efc67cee700b89ffbdb74a0603a083ec1290ae31
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dc794e878e6d79f75205be456b1042a289c5759ddc794e878e6d79f75205be456b1042a289c5759d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1e5a17dc77d8a8bbe67040b32e2ef755901aba441e5a17dc77d8a8bbe67040b32e2ef755901aba44
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b3959d5eca136e0588f9af3867b34032160cb826b3959d5eca136e0588f9af3867b34032160cb826
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 23c4cb8a56978e5b1baa171d42e616e316c2039d23c4cb8a56978e5b1baa171d42e616e316c2039d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dc2d5f02636c7587bdd6d1f60fc59c55860b00a4dc2d5f02636c7587bdd6d1f60fc59c55860b00a4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < adb1f312f38f0d2c928ceaff089262798cc260b4adb1f312f38f0d2c928ceaff089262798cc260b4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f956052e00de211b5c9ebaa1958366c23f82ee9ef956052e00de211b5c9ebaa1958366c23f82ee9e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.3 < 6.6.586.6.58
linuxlinux_kernel>= 6.7 < 6.11.56.11.5
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.