Out-of-Bounds Read in Linux Kernel's XFRM Implementation
CVE-2024-57982

7.1HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 February 2025

What is CVE-2024-57982?

A vulnerability in the Linux Kernel's XFRM implementation allows for an out-of-bounds read during state lookups, which may occur when multiple processes attempt to access the same state concurrently. This issue arises from an inconsistency in the hash function and the state hash mask, potentially leading to undefined behavior. The vulnerability has been addressed by ensuring that the hash state mask and pointers are prefetched, thus maintaining consistency during lookup processes. It is crucial for users to apply security patches promptly to mitigate associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux c2f672fc94642bae96821a393f342edcfa9794a6

Linux c2f672fc94642bae96821a393f342edcfa9794a6

Linux c2f672fc94642bae96821a393f342edcfa9794a6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.