CVE-2024-46740: binder: fix UAF caused by offsets overwrite
binder: fix UAF caused by offsets overwrite
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46740?
CVE-2024-46740 has a high severity rating due to the potential for user-after-free (UAF) vulnerabilities that can be exploited.
How do I fix CVE-2024-46740?
To mitigate CVE-2024-46740, update your Linux kernel to a patched version such as 5.10.226 or higher, depending on your specific distribution.
Which systems are affected by CVE-2024-46740?
CVE-2024-46740 affects multiple versions of the Linux kernel, specifically those between 5.4.226 and 6.11-rc6.
What types of exploitation can occur with CVE-2024-46740?
Exploitation of CVE-2024-46740 could lead to arbitrary code execution or potentially escalate user privileges.
Is CVE-2024-46740 related to Android vulnerabilities?
Yes, CVE-2024-46740 affects Google Android due to its reliance on the underlying Linux kernel.