CVE-2024-43815

HIGH

Linux Kernel 6.10-6.10.2 - Uninitialized Memory Leak in mxs-dcp AES Key Slot Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - Ensure payload is zero when using key slot We could leak stack memory through the payload field when running AES with a key from one of the hardware's key slots. Fix this by ensuring the payload field is set to 0 in such cases. This does not affect the common use case when the key is supplied from main memory via the descriptor payload.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-908
Status published
Products (8)
linux/Kernel 6.10.0 - 6.10.3linux
Linux/Linux < 6.10
Linux/Linux 3d16af0b4cfac4b2c3b238e2ec37b38c2f316978 - dd52b5eeb0f70893f762da7254e923fd23fd1379
Linux/Linux 3d16af0b4cfac4b2c3b238e2ec37b38c2f316978 - e1640fed0377bf7276efb70d03cb821a6931063d
Linux/Linux 6.10
Linux/Linux 6.10.3 - 6.10.*
Linux/Linux 6.11
linux/linux_kernel 6.10 - 6.10.3
Published Aug 17, 2024
Tracked Since Feb 18, 2026