cbcvebase.
CVE-2024-53101
published 2024-11-25

CVE-2024-53101: In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in a trace point even though ATTR_MODE, ATTR_UID and ATTR_GID aren't set. Initialize all fields of newattrs to avoid uninitialized variables, by checking if ATTR_MODE, ATTR_UID, ATTR_GID are initialized, otherwise 0.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < a0c77e5e3dcbffc7c6080ccc89c037f0c86496cfa0c77e5e3dcbffc7c6080ccc89c037f0c86496cf
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < 17ecb40c5cc7755a321fb6148cba5797431ee5b817ecb40c5cc7755a321fb6148cba5797431ee5b8
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < 9db25c2b41c34963c3ccf473b08171f87670652e9db25c2b41c34963c3ccf473b08171f87670652e
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < b3e612bd8f64ce62e731e95f635e06a2efe3c80cb3e612bd8f64ce62e731e95f635e06a2efe3c80c
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < 5a72b0d3497b818d8f000c347a7c11801eb27bfc5a72b0d3497b818d8f000c347a7c11801eb27bfc
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < 1cb5bfc5bfc651982b6203c224d49b7ddacf28bc1cb5bfc5bfc651982b6203c224d49b7ddacf28bc
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < 1c28bca1256aecece6e94b26b85cd07e08b0dc901c28bca1256aecece6e94b26b85cd07e08b0dc90
linuxlinux>= 468eedde23d6c9335935773f4f5764267d5a7763 < 15f34347481648a567db67fb473c23befb796af515f34347481648a567db67fb473c23befb796af5
linuxlinux_kernel< 4.19.3244.19.324
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2865.4.286
linuxlinux_kernel>= 5.11 < 5.15.1735.15.173
linuxlinux_kernel>= 5.16 < 6.1.1186.1.118
linuxlinux_kernel>= 5.5 < 5.10.2305.10.230

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.