CVE-2024-43868

MEDIUM

Linux Kernel 5.19-5.19, 6.2-6.6.61, 6.7-6.10.4 - Denial of Service via Unaligned Purgatory Exception

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: riscv/purgatory: align riscv_kernel_entry When alignment handling is delegated to the kernel, everything must be word-aligned in purgatory, since the trap handler is then set to the kexec one. Without the alignment, hitting the exception would ultimately crash. On other occasions, the kernel's handler would take care of exceptions. This has been tested on a JH7110 SoC with oreboot and its SBI delegating unaligned access exceptions and the kernel configured to handle them.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
linux/Kernel 5.19.0 - 6.1.117linux
linux/Kernel 6.2.0 - 6.6.61linux
linux/Kernel 6.7.0 - 6.10.4linux
Linux/Linux < 5.19
Linux/Linux 5.19
Linux/Linux 6.1.117 - 6.1.*
Linux/Linux 6.10.4 - 6.10.*
Linux/Linux 6.11
Linux/Linux 6.6.61 - 6.6.*
Linux/Linux 736e30af583fb6e0e2b8211b894ff99dea0f1ee7 - 10ffafb456f293976c42f700578ef740467cb569
... and 5 more
Published Aug 21, 2024
Tracked Since Feb 18, 2026