CVE-2024-53155Use of Uninitialized Resource in Linux

Severity
7.1HIGHNVD
OSV8.8OSV7.8OSV5.5
EPSS
0.0%
top 98.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_iter() Syzbot has reported the following KMSAN splat: BUG: KMSAN: uninit-value in ocfs2_file_read_iter+0x9a4/0xf80 ocfs2_file_read_iter+0x9a4/0xf80 __io_read+0x8d4/0x20f0 io_read+0x3e/0xf0 io_issue_sqe+0x42b/0x22c0 io_wq_submit_work+0xaf9/0xdc0 io_worker_handle_work+0xd13/0x2110 io_wq_worker+0x447/0x1410 ret_from_fork+0x6f/0x90 ret_from_fork_asm+0x1a/0x30 Uninit was created a

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages9 packages

NVDlinux/linux_kernel2.6.224.19.325+7
Debianlinux/linux_kernel< 5.10.234-1+3
Ubuntulinux/linux_kernel< 5.4.0-211.231+5
CVEListV5linux/linux7cdfc3a1c3971c9125c317cb8c2525745851798e6c8f8d1e595dabd5389817f6d798cc8bd95c40ab+9

Patches

🔴Vulnerability Details

45
OSV
linux-azure, linux-azure-4.15 vulnerabilities2025-06-09
OSV
linux-azure-fips vulnerabilities2025-06-09
OSV
linux-azure vulnerabilities2025-06-09
OSV
linux-fips vulnerabilities2025-06-06
OSV
linux-aws, linux-lts-xenial vulnerabilities2025-06-04

📋Vendor Advisories

46
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (Azure) vulnerabilities2025-06-09
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-06-09
Ubuntu
Linux kernel (Azure) vulnerabilities2025-06-09
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-06-06
CVE-2024-53155 — Use of Uninitialized Resource in Linux | cvebase