First published: Thu May 30 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: i40e: fix vf may be used uninitialized in this function warning The Linux kernel CVE team has assigned <a href="https://access.redhat.com/security/cve/CVE-2024-36020">CVE-2024-36020</a> to this issue. Upstream advisory: <a href="https://lore.kernel.org/linux-cve-announce/2024053044-CVE-2024-36020-5da7@gregkh/T">https://lore.kernel.org/linux-cve-announce/2024053044-CVE-2024-36020-5da7@gregkh/T</a>
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <4.19.312 | 4.19.312 |
redhat/kernel | <5.4.274 | 5.4.274 |
redhat/kernel | <5.10.215 | 5.10.215 |
redhat/kernel | <5.15.154 | 5.15.154 |
redhat/kernel | <6.1.85 | 6.1.85 |
redhat/kernel | <6.6.26 | 6.6.26 |
redhat/kernel | <6.8.5 | 6.8.5 |
redhat/kernel | <6.9 | 6.9 |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-36020 is classified as low due to the nature of the vulnerability.
To fix CVE-2024-36020, update to the latest kernel version specified in the advisory or apply available patches.
CVE-2024-36020 affects several versions of the Linux kernel including 4.19.312, 5.4.274, and others up to 6.9.
The impact of CVE-2024-36020 on system security primarily involves potential uninitialized variable usage which could lead to unexpected behavior.
CVE-2024-36020 impacts various Linux distributions utilizing the affected kernel versions such as Red Hat and Debian.