CVE-2024-42157: s390/pkey: Wipe sensitive data on failure
Published Jul 30, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
s390/pkey: Wipe sensitive data on failure
Wipe sensitive data from stack also if the copytouser() fails.
Affected Software
14 affected componentsFixes available
Linux Linux kernel>=4.11<4.19.318
Linux Linux kernel>=4.20<5.4.280
Linux Linux kernel>=5.5<5.10.222
Linux Linux kernel>=5.11<5.15.163
Linux Linux kernel>=5.16<6.1.98
Linux Linux kernel>=6.2<6.6.39
Linux Linux kernel>=6.7<6.9.9
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Microsoft cbl2 kernel 5.15.162.2-1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft azl3 kernel 6.6.35.1-5
Microsoft cbl2 kernel 5.15.162.2-1
Microsoft azl3 kernel 6.6.43.1-7
Remediation
Event History
Jul 30, 2024
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
Description
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityAffected Software
Aug 16, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
May 7, 2025
Data Sourced
via Ubuntu·06:23 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42157?
CVE-2024-42157 has been rated as a moderate severity vulnerability in the Linux kernel.
2
How do I fix CVE-2024-42157?
To address CVE-2024-42157, update your Linux kernel to the fixed versions listed in the official advisories.
3
Which versions of the Linux kernel are affected by CVE-2024-42157?
CVE-2024-42157 affects several Linux kernel versions prior to the patched releases including those listed in the vulnerability report.
4
What component of the Linux kernel is impacted by CVE-2024-42157?
CVE-2024-42157 impacts the s390/pkey component of the Linux kernel.
5
Is CVE-2024-42157 a local or remote vulnerability?
CVE-2024-42157 is considered a local vulnerability as it requires local access to the system to exploit.