CVE-2024-50076

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/10/2024
Last modified:
08/11/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> vt: prevent kernel-infoleak in con_font_get()<br /> <br /> font.data may not initialize all memory spaces depending on the implementation<br /> of vc-&gt;vc_sw-&gt;con_font_get. This may cause info-leak, so to prevent this, it<br /> is safest to modify it to initialize the allocated memory space to 0, and it<br /> generally does not affect the overall performance of the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.3 (including) 6.6.58 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.11.5 (excluding)
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:*