Wind River Support Network

HomeDefectsLIN1023-6773
Fixed

LIN1023-6773 : Security Advisory - linux - CVE-2024-38619

Created: Jun 20, 2024    Updated: Jul 2, 2024
Resolved Date: Jun 27, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.12
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

usb-storage: alauda: Check whether the media is initialized

The member "uzonesize" of struct alauda_info will remain 0
if alauda_init_media() fails, potentially causing divide errors
in alauda_read_data() and alauda_write_lba().
- Add a member "media_initialized" to struct alauda_info.
- Change a condition in alauda_check_media() to ensure the
  first initialization.
- Add an error check for the return value of alauda_init_media().

CREATE(Triage):(User=admin) CVE-2024-38619 (https://nvd.nist.gov/vuln/detail/CVE-2024-38619)

CVEs


Live chat
Online