Bug 2301523 (CVE-2024-42155)
Summary: | CVE-2024-42155 kernel: s390/pkey: Wipe copies of protected- and secure-keys | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | dfreiber, drow, jburrell, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kernel 6.9.9, kernel 6.10 | Doc Type: | If docs needed, set a value |
Doc Text: |
A vulnerability was found in the Linux kernel's s390 crypto driver where improper secret management lead to protected and secure keys not properly being cleared from memory, allowing the sensitive material to be accessible through memory inspection under specific error conditions. This vulnerability could potentially lead to sensitive information disclosure.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2302023 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2024-07-30 08:41:10 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024073035-CVE-2024-42155-5ccb@gregkh/T Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2302023] |