CVE-2024-39478: crypto: starfive - Do not free stack buffer
crypto: starfive - Do not free stack buffer
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39478?
CVE-2024-39478 is a vulnerability in the Linux kernel that can lead to undefined behavior due to improper handling of a stack buffer.
How do I fix CVE-2024-39478?
To fix CVE-2024-39478, update your Linux kernel to the recommended secure versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Which Linux kernel versions are affected by CVE-2024-39478?
CVE-2024-39478 affects all versions of the Linux kernel from 6.9 to 6.9.5, specifically those versions utilizing the starfive crypto implementation.
What types of applications could be impacted by CVE-2024-39478?
Applications that rely on RSA text data within the affected Linux kernel versions may encounter crashes or unexpected behavior due to this vulnerability.
Is CVE-2024-39478 exploitable remotely?
The exploitability of CVE-2024-39478 potentially depends on the specific application context and the attack vector but could lead to significant impacts if exploited.