CVE-2024-42157

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Jul 30, 2024
Updated: Aug 2, 2024

Summary

CVE-2024-42157 is a recently identified vulnerability in the Linux kernel. This issue involves the s390/pkey driver, where sensitive data is not properly handled during a copy operation. Specifically, if the copy_to_user() function fails, the data is still wiped from the stack. This behavior can lead to unintended data exposure, potentially allowing attackers to gain sensitive information or cause other security issues. The vulnerability has been resolved in the latest kernel updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share