Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/tcp_ao: Don't leak ao_info on error-path It seems I introduced it together with TCP_AO_CMDF_AO_REQUIRED, on version 5 [1] of TCP-AO patches. Quite frustrative that having all these selftests that I've written, running kmemtest & kcov was always in todo. [1]: https://lore.kernel.org/netdev/[email protected]/
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.7, < 6.9.7 |
References
- https://git.kernel.org/stable/c/ebaa7d3c26332330a48f9a15f8e518d526cc0f21Patch
- https://git.kernel.org/stable/c/f9ae848904289ddb16c7c9e4553ed4c64300de49Patch
- https://git.kernel.org/stable/c/ebaa7d3c26332330a48f9a15f8e518d526cc0f21Patch
- https://git.kernel.org/stable/c/f9ae848904289ddb16c7c9e4553ed4c64300de49Patch
FAQ
What is CVE-2024-40985?
CVE-2024-40985 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: net/tcp_ao: Don't leak ao_info on error-path It seems I introduced it together with TCP_AO_CMDF_AO_REQUIRED, on version 5 [1] of T...
How severe is CVE-2024-40985?
CVE-2024-40985 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40985?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.