Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-36288
HistoryJun 21, 2024 - 12:00 a.m.

CVE-2024-36288

2024-06-2100:00:00
ubuntu.com
ubuntu.com
4
linux kernel
sunrpc
vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

In the Linux kernel, the following vulnerability has been resolved: SUNRPC:
Fix loop termination condition in gss_free_in_token_pages() The
in_token->pages[] array is not NULL terminated. This results in the
following KASAN splat: KASAN: maybe wild-memory-access in range
[0x04a2013400000008-0x04a201340000000f]

OSVersionArchitecturePackageVersionFilename
ubuntu24.04noarchlinux< anyUNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High