CVE-2024-44966: binfmt_flat: Fix corruption when not offsetting data start
binfmtflat: Fix corruption when not offsetting data start
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44966?
CVE-2024-44966 is classified as a moderate severity vulnerability in the Linux kernel.
Which versions of the Linux kernel are affected by CVE-2024-44966?
CVE-2024-44966 affects Linux kernel versions 5.13 to 5.15.165, 5.16 to 6.1.106, 6.2 to 6.6.47, and 6.7 to 6.10.6, as well as specific release candidates.
How do I fix CVE-2024-44966?
To mitigate CVE-2024-44966, update your Linux kernel to a patched version such as 5.10.223-1 or 6.12.11-1.
What type of vulnerability is CVE-2024-44966?
CVE-2024-44966 is a data corruption vulnerability specifically related to the binfmt_flat feature in the Linux kernel.
Is CVE-2024-44966 specific to any architecture?
Yes, CVE-2024-44966 has a specific variant for the RISC-V architecture within the FLAT format.