CVE-2024-57931

MEDIUM

Linux Kernel 4.3-6.12.8 DoS via SELinux Extended Permission Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: selinux: ignore unknown extended permissions When evaluating extended permissions, ignore unknown permissions instead of calling BUG(). This commit ensures that future permissions can be added without interfering with older kernels.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (24)
linux/Kernel 4.3.0 - 5.4.289linux
linux/Kernel 5.11.0 - 5.15.176linux
linux/Kernel 5.16.0 - 6.1.124linux
linux/Kernel 5.5.0 - 5.10.233linux
linux/Kernel 6.2.0 - 6.6.70linux
linux/Kernel 6.7.0 - 6.12.9linux
Linux/Linux < 4.3
Linux/Linux 4.3
Linux/Linux 5.10.233 - 5.10.*
Linux/Linux 5.15.176 - 5.15.*
... and 14 more
Published Jan 21, 2025
Tracked Since Feb 18, 2026