CVE-2024-42155: s390/pkey: Wipe copies of protected- and secure-keys
In the Linux kernel, the following vulnerability has been resolved:
s390/pkey: Wipe copies of protected- and secure-keys
Although the clear-key of neither protected- nor secure-keys is accessible, this key material should only be visible to the calling process. So wipe all copies of protected- or secure-keys from stack, even in case of an error.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42155?
CVE-2024-42155 has been classified with a severity rating that indicates it poses risks to the confidentiality of sensitive key material in the Linux kernel.
How do I fix CVE-2024-42155?
To fix CVE-2024-42155, update to Linux kernel versions 6.12.11-1 or 6.12.12-1, or ensure your system is upgraded beyond version 6.9.9.
Which versions of Linux are affected by CVE-2024-42155?
CVE-2024-42155 affects Linux kernel versions from 4.11 up to 6.9.9.
What are protected-keys and secure-keys in relation to CVE-2024-42155?
Protected-keys and secure-keys are mechanisms in the Linux kernel that manage access to sensitive cryptographic keys, which are at risk due to this vulnerability.
Who is impacted by CVE-2024-42155?
Organizations and individuals using affected versions of the Linux kernel may be impacted by CVE-2024-42155, particularly those relying on protected and secure-key functionalities.