CVE-2024-36898: gpiolib: cdev: fix uninitialised kfifo
gpiolib: cdev: fix uninitialised kfifo
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36898?
CVE-2024-36898 has been classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-36898?
To remediate CVE-2024-36898, ensure that you upgrade to the latest patched versions of the Linux kernel, specifically 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
Which Linux kernel versions are affected by CVE-2024-36898?
CVE-2024-36898 affects Linux kernel versions up to 5.10.226-1, inclusive.
What is the cause of CVE-2024-36898?
CVE-2024-36898 is caused by an issue in the gpiolib related to uninitialized kfifo when configuring edge detection after software debouncing.
Is CVE-2024-36898 currently exploited in the wild?
As of now, there are no public reports indicating that CVE-2024-36898 is actively being exploited in the wild.