CVE-2024-42312
Published: Aug 17, 2024
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: sysctl: always initialize i_uid/i_gid Always initialize i_uid/i_gid inside the sysfs core so set_ownership() can safely skip setting them. Commit 5ec27ec735ba ("fs/proc/proc_sysctl.c: fix the default values of i_uid/i_gid on /proc/sys inodes.") added defaults for i_uid/i_gid when set_ownership() was not implemented. It also missed adjusting net_ctl_set_ownership() to use the same default values in case the computation of a better value failed.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf - < b2591c89a6e2858796111138c38fcb6851aa1955affected 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf - < 34a86adea1f2b3c3f9d864c8cce09dca644601abaffected 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf - < 1deae34db9f4f8e0e03f891be2e2e15c15c8ac05affected 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf - < ffde3af4b29bf97d62d82e1d45275587e10a991aaffected 5ec27ec735ba0477d48c80561cc5e856f0c5dfaf - < c7e2f43d182f5dde473389dbb39f16c9f0d64536+11 more versions |
Linux | Linux | affected 5.3unaffected 0 - < 5.3unaffected 5.10.224 - <= 5.10.*unaffected 5.15.165 - <= 5.15.*unaffected 6.1.104 - <= 6.1.*+3 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now