Memory Access Vulnerability in Linux Kernel's Server Proposal Message Handling
CVE-2024-47408

9.8CRITICAL

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 January 2025

What is CVE-2024-47408?

In the Linux kernel, a vulnerability exists when handling proposal messages from remote clients. Specifically, the field smcd_v2_ext_offset, sourced from the client, is not fully validated before use. If this value exceeds its maximum limit, it can lead to accessing invalid memory addresses, potentially resulting in a crash of the server. A patch has been implemented to thoroughly check the smcd_v2_ext_offset value to enhance security and prevent such occurrences.

Affected Version(s)

Linux 5c21c4ccafe85906db809de3af391fd434df8a27

Linux 5c21c4ccafe85906db809de3af391fd434df8a27

Linux 5c21c4ccafe85906db809de3af391fd434df8a27 < 935caf324b445fe73d7708fae6f7176fb243f357

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.