cbcvebase.
CVE-2024-57911
published 2025-01-19

CVE-2024-57911: In the Linux kernel, the following vulnerability has been resolved: iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer The 'data'…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer The 'data' array is allocated via kmalloc() and it is used to push data to user space from a triggered buffer, but it does not set values for inactive channels, as it only uses iio_for_each_active_channel() to assign new values. Use kzalloc for the memory allocation to avoid pushing uninitialized information to userspace.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < 03fa47621bf8fcbf5994c5716021527853f9af3d03fa47621bf8fcbf5994c5716021527853f9af3d
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < e1c1e8c05010103c9c9ea3e9c4304b0b7e2c8e4ae1c1e8c05010103c9c9ea3e9c4304b0b7e2c8e4a
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < 006073761888a632c5d6f93e47c41760fa627f77006073761888a632c5d6f93e47c41760fa627f77
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < b0642d9c871aea1f28eb02cd84d60434df594f67b0642d9c871aea1f28eb02cd84d60434df594f67
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < 74058395b2c63c8a438cf199d09094b640f8c7f474058395b2c63c8a438cf199d09094b640f8c7f4
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < ea703cda36da0dacb9a2fd876370003197d8a019ea703cda36da0dacb9a2fd876370003197d8a019
linuxlinux>= 415f792447572ef1949a3cef5119bbce8cc66373 < 333be433ee908a53f283beb95585dfc14c8ffb46333be433ee908a53f283beb95585dfc14c8ffb46
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 4.5 < 5.4.2905.4.290
linuxlinux_kernel>= 5.11 < 5.15.1775.15.177
linuxlinux_kernel>= 5.16 < 6.1.1256.1.125
linuxlinux_kernel>= 5.5 < 5.10.2345.10.234
linuxlinux_kernel>= 6.2 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.