Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-06235
HistoryJan 12, 2024 - 12:00 a.m.

Linux kernel code issue vulnerability (CNVD-2024-06235)

2024-01-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
20
linux
open source
operating system
code issue
vulnerability
memory initialization
exploitation
locally privileged attacker
kernel memory

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Linux kernel is the kernel used by Linux, the open source operating system of the Linux Foundation in the United States. A code issue vulnerability exists in the Linux kernel that stems from vhost_new_msg in drivers/vhost/vhost.c failing to properly initialize memory in messages passed between a virtual client and the host operating system, which could be exploited by a locally-privileged attacker to read the contents of certain kernel memory.

CPENameOperatorVersion
linux linux kernellt6.4