Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-42225

Опубликовано: 30 июл. 2024
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

A potential flaw was found in the Linux kernel’s MediaTek WiFi, where it was reusing uninitialized data. This flaw allows a local user to gain unauthorized access to some data potentially.

Отчет

Red Hat Enterprise Linux 8.10 and later are affected.

Меры по смягчению последствий

To mitigate this issue, prevent module mt76 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernel-rtAffected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 8kernelFixedRHSA-2024:700024.09.2024
Red Hat Enterprise Linux 9kernelFixedRHSA-2024:699724.09.2024
Red Hat Enterprise Linux 9kernelFixedRHSA-2024:699724.09.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-457
https://bugzilla.redhat.com/show_bug.cgi?id=2301543kernel: wifi: mt76: replace skb_put with skb_put_zero

EPSS

Процентиль: 36%
0.00143
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS3: 7.5
nvd
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: w ...

CVSS3: 7.5
github
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

EPSS

Процентиль: 36%
0.00143
Низкий

4.8 Medium

CVSS3