CVE Database
/

CVE-2024-41079

Back to search

CVE-2024-41079

Published: Jul 29, 2024

Modified: Jun 1, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet: always initialize cqe.result The spec doesn't mandate that the first two double words (aka results) for the command queue entry need to be set to 0 when they are not used (not specified). Though, the target implemention returns 0 for TCP and FC but not for RDMA. Let's make RDMA behave the same and thus explicitly initializing the result field. This prevents leaking any data from the stack.

VendorProductVersions

Linux

Linux

affected
a07b4970f464f13640e28e16dad6cfa33647cc99 - < c6a2cf8b0764f3ba7d9bff58c8775a6d4476bb29
affected
a07b4970f464f13640e28e16dad6cfa33647cc99 - < 30d35b24b7957922f81cfdaa66f2e1b1e9b9aed2
affected
a07b4970f464f13640e28e16dad6cfa33647cc99 - < 10967873b80742261527a071954be8b54f0f8e4d
affected
a07b4970f464f13640e28e16dad6cfa33647cc99 - < 0990e8a863645496b9e3f91cfcfd63cd95c80319
affected
a07b4970f464f13640e28e16dad6cfa33647cc99 - < cd0c1b8e045a8d2785342b385cb2684d9b48e426

Linux

Linux

affected
4.8
unaffected
0 - < 4.8
unaffected
5.15.209 - <= 5.15.*
unaffected
6.1.101 - <= 6.1.*
unaffected
6.6.42 - <= 6.6.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now