CVE-2024-53082: virtio_net: Add hash_key_length check
In the Linux kernel, the following vulnerability has been resolved:
virtionet: Add hashkeylength check
Add hashkeylength check in virtnetprobe() to avoid possible out of bound errors when setting/reading the hash key.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53082?
CVE-2024-53082 is classified as a medium severity vulnerability affecting the Linux kernel.
How do I fix CVE-2024-53082?
To address CVE-2024-53082, update your Linux kernel to the latest patched version that includes the hash_key_length check.
What software is affected by CVE-2024-53082?
CVE-2024-53082 affects the Linux kernel versions between 5.18 and 6.1.117, as well as several versions from 6.2 to 6.12-rc6.
What type of vulnerability is CVE-2024-53082?
CVE-2024-53082 is a potential out-of-bounds write vulnerability related to the virtio_net driver in the Linux kernel.
When was CVE-2024-53082 reported?
CVE-2024-53082 was reported as part of updates to the Linux kernel in 2024.