CVE-2024-41079
Published: Jul 29, 2024
Modified: Jun 1, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: nvmet: always initialize cqe.result The spec doesn't mandate that the first two double words (aka results) for the command queue entry need to be set to 0 when they are not used (not specified). Though, the target implemention returns 0 for TCP and FC but not for RDMA. Let's make RDMA behave the same and thus explicitly initializing the result field. This prevents leaking any data from the stack.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected a07b4970f464f13640e28e16dad6cfa33647cc99 - < c6a2cf8b0764f3ba7d9bff58c8775a6d4476bb29affected a07b4970f464f13640e28e16dad6cfa33647cc99 - < 30d35b24b7957922f81cfdaa66f2e1b1e9b9aed2affected a07b4970f464f13640e28e16dad6cfa33647cc99 - < 10967873b80742261527a071954be8b54f0f8e4daffected a07b4970f464f13640e28e16dad6cfa33647cc99 - < 0990e8a863645496b9e3f91cfcfd63cd95c80319affected a07b4970f464f13640e28e16dad6cfa33647cc99 - < cd0c1b8e045a8d2785342b385cb2684d9b48e426 |
Linux | Linux | affected 4.8unaffected 0 - < 4.8unaffected 5.15.209 - <= 5.15.*unaffected 6.1.101 - <= 6.1.*unaffected 6.6.42 - <= 6.6.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now