CVE-2024-42080

MEDIUM

Linux Kernel < 5.15.162, 5.16.0-6.1.97, 6.2.0-6.6.37, 6.7.0-6.9.8 - Out-of-bounds Write in RDMA Restrack Entry

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/restrack: Fix potential invalid address access struct rdma_restrack_entry's kern_name was set to KBUILD_MODNAME in ib_create_cq(), while if the module exited but forgot del this rdma_restrack_entry, it would cause a invalid address access in rdma_restrack_clean() when print the owner of this rdma_restrack_entry. These code is used to help find one forgotten PD release in one of the ULPs. But it is not needed anymore, so delete them.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (17)
linux/Kernel 4.17.0 - 5.15.162linux
linux/Kernel 5.16.0 - 6.1.97linux
linux/Kernel 6.2.0 - 6.6.37linux
linux/Kernel 6.7.0 - 6.9.8linux
Linux/Linux < 4.17
Linux/Linux 03286030ac0420c759fa25f5b976e40293bccaaf - 782bdaf9d01658281bc813f3f873e6258aa1fd8d
Linux/Linux 03286030ac0420c759fa25f5b976e40293bccaaf - 8656ef8a9288d6c932654f8d3856dc4ab1cfc6b5
Linux/Linux 03286030ac0420c759fa25f5b976e40293bccaaf - 8ac281d42337f36cf7061cf1ea094181b84bc1a9
Linux/Linux 03286030ac0420c759fa25f5b976e40293bccaaf - ca537a34775c103f7b14d7bbd976403f1d1525d8
Linux/Linux 03286030ac0420c759fa25f5b976e40293bccaaf - f45b43d17240e9ca67ebf3cc82bb046b07cc1c61
... and 7 more
Published Jul 29, 2024
Tracked Since Feb 18, 2026