CVE-2024-23849: Medium severity Linux Linux kernel vulnerability
In rdsrecvtracklatency in net/rds/afrds.c in the Linux kernel through 6.7.1 there is an off-by-one error for an RDSMSGRXDGRAMTRACEMAX comparison resulting in out-of-bounds access.
Other sources
In rdsrecvtracklatency in net/rds/afrds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDSMSGRXDGRAMTRACEMAX comparison, resulting in out-of-bounds access.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23849?
CVE-2024-23849 is classified as a high-severity vulnerability due to its potential for out-of-bounds access in the Linux kernel.
How do I fix CVE-2024-23849?
To mitigate CVE-2024-23849, upgrade to a patched version of the Linux kernel, specifically versions newer than 6.7.1.
What systems are affected by CVE-2024-23849?
CVE-2024-23849 affects Linux kernel versions up to and including 6.7.1.
Who reported CVE-2024-23849?
CVE-2024-23849 was reported by Sharath Srinivasan from Oracle.
What does the CVE-2024-23849 vulnerability involve?
CVE-2024-23849 involves an off-by-one error that leads to out-of-bounds access in the rds_recv_track_latency function.