CVE-2024-57874 — Use of Uninitialized Resource in Linux
CWE-908 — Use of Uninitialized ResourceCWE-824 — Access of Uninitialized Pointer56 documents7 sources
Severity
6.1MEDIUMNVD
OSV8.8OSV7.8
EPSS
0.0%
top 96.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateAug 14
Description
In the Linux kernel, the following vulnerability has been resolved:
arm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL
Currently tagged_addr_ctrl_set() doesn't initialize the temporary 'ctrl'
variable, and a SETREGSET call with a length of zero will leave this
uninitialized. Consequently tagged_addr_ctrl_set() will consume an
arbitrary value, potentially leaking up to 64 bits of memory from the
kernel stack. The read is limited to a specific slot on the stack, and
the issue does …
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:HExploitability: 1.8 | Impact: 4.2
Affected Packages6 packages
▶CVEListV5linux/linux2200aa7154cb7ef76bac93e98326883ba64bfa2e — 1152dd13845efde5554f80c7e1233bae1d26bd3e+6