Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-36481
HistoryJun 21, 2024 - 12:00 a.m.

CVE-2024-36481

2024-06-2100:00:00
ubuntu.com
ubuntu.com
10
linux kernel
vulnerability
resolved
parsing
error check
tracing
probes
btf
struct member

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.5

Confidence

High

In the Linux kernel, the following vulnerability has been resolved:
tracing/probes: fix error check in parse_btf_field()
btf_find_struct_member() might return NULL or an error via the ERR_PTR()
macro. However, its caller in parse_btf_field() only checks for the NULL
condition. Fix this by using IS_ERR() and returning the error up the stack.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.5

Confidence

High