CVE-2024-41052: vfio/pci: Init the count variable in collecting hot-reset devices
In the Linux kernel, the following vulnerability has been resolved:
vfio/pci: Init the count variable in collecting hot-reset devices
The count variable is used without initialization, it results in mistakes in the device counting and crashes the userspace if the get hot reset info path is triggered.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41052?
CVE-2024-41052 has been evaluated and reported to pose a moderate severity risk due to potential device miscounting and user space crashes.
How can I fix CVE-2024-41052?
To mitigate CVE-2024-41052, upgrade your Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
Which Linux kernel versions are affected by CVE-2024-41052?
CVE-2024-41052 affects Linux kernel versions between 6.6.36 to 6.6.41 and between 6.9.7 to 6.9.10.
What impact does CVE-2024-41052 have on the system?
CVE-2024-41052 can cause incorrect device counting leading to user space crashes when attempting to retrieve hot reset information.
Is there a patch available for CVE-2024-41052?
Yes, patches are available in the specified versions of the Linux kernel to resolve the issues related to CVE-2024-41052.