CVE-2024-53082
HIGH severity · CVSS 8.4 · Out-of-bounds read
8.4CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key_length check in virtnet_probe() to avoid possible out of bound errors when setting/reading the hash key.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/3f7d9c1964fcd16d02a8a9d4fd6f6cb60c4cc530 ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/3f7d9c1964fcd16d02a8a9d4fd6f6cb60c4cc530Patch
- https://git.kernel.org/stable/c/6a18a783b1fa590ad1ed785907263e4b86adcfe2Patch
- https://git.kernel.org/stable/c/af0aa8aecbe8985079232902894cc4cb62795691Patch
- https://git.kernel.org/stable/c/f3401e3c8d339ddb6ccb2e3d11ad634b7846a806Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html