CVE-2024-42311: hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
hfs: fix to initialize fields of hfsinodeinfo after hfsallocinode()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42311?
CVE-2024-42311 has a severity rating that may allow for uninitialized value access in the Linux kernel.
How do I fix CVE-2024-42311?
To resolve CVE-2024-42311, update your Linux kernel to a version that includes the patch, such as 5.10.226-1 or 6.1.123-1.
Which Linux kernel versions are affected by CVE-2024-42311?
CVE-2024-42311 affects multiple Linux kernel versions, including versions between 4.19.320 and 6.10.3.
Is there a temporary workaround for CVE-2024-42311?
There is no recommended temporary workaround for CVE-2024-42311 aside from applying the appropriate kernel updates.
What components are involved in CVE-2024-42311?
CVE-2024-42311 specifically involves the hfs filesystem in the Linux kernel.