CVE-2024-38381

HIGH

Linux Kernel - Use of Uninitialized Resource in NFC NCI rx_work Packet Processing

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header size, payload size and total packet size before processing the packet. If an invalid packet is detected, it should be silently discarded.

Scores

CVSS v3 7.1
EPSS 0.0026
EPSS Percentile 16.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-908
Status published
Products (34)
linux/Kernel < 4.19.316linux
linux/Kernel 4.20.0 - 5.4.278linux
linux/Kernel 5.11.0 - 5.15.161linux
linux/Kernel 5.16.0 - 6.1.93linux
linux/Kernel 5.5.0 - 5.10.219linux
linux/Kernel 6.2.0 - 6.6.33linux
linux/Kernel 6.7.0 - 6.9.4linux
Linux/Linux < 6.9
Linux/Linux 03fe259649a551d336a7f20919b641ea100e3fff - 485ded868ed62ceb2acb3a459d7843fd71472619
Linux/Linux 11387b2effbb55f58dc2111ef4b4b896f2756240 - 406cfac9debd4a6d3dc5d9258ee086372a8c08b6
... and 24 more
Published Jun 21, 2024
Tracked Since Feb 18, 2026