cbcvebase.
CVE-2024-57908
published 2025-01-19

CVE-2024-57908: In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered buffer The 'buffer' local array is used…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
11.9th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered buffer The 'buffer' local array is used to push data to user space from a triggered buffer, but it does not set values for inactive channels, as it only uses iio_for_each_active_channel() to assign new values. Initialize the array to zero before using it to avoid pushing uninitialized information to userspace.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < 0871eb8d700b33dd7fa86c80630d62ddaef58c2c0871eb8d700b33dd7fa86c80630d62ddaef58c2c
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < a386d9d2dc6635f2ec210b8199cfb3acf4d31305a386d9d2dc6635f2ec210b8199cfb3acf4d31305
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < a07f698084412a3ef5e950fcac1d6b0f53289efda07f698084412a3ef5e950fcac1d6b0f53289efd
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < 6985ba4467e4b15b809043fa7740d1fb23a1897b6985ba4467e4b15b809043fa7740d1fb23a1897b
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < cde312e257b59ecaa0fad3af9ec7e2370bb24639cde312e257b59ecaa0fad3af9ec7e2370bb24639
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < 565814cbbaa674d2901428796801de49a611e59d565814cbbaa674d2901428796801de49a611e59d
linuxlinux>= c3a23ecc0901f624b681bbfbc4829766c5aa3070 < 6ae053113f6a226a2303caa4936a4c37f3bfff7b6ae053113f6a226a2303caa4936a4c37f3bfff7b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 4.0 < 6.1.1256.1.125
linuxlinux_kernel>= 6.2 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.