CVE-2024-39488 is a vulnerability in the Linux kernel, specifically affecting arm64 architectures when CONFIG_DEBUG_BUGVERBOSE is disabled. It stems from incorrect padding of bug_entry structures within kernel modules, causing the last entry in a bug table to be ignored. This can lead to an unexpected kernel panic when a module attempts to handle a bug that is not properly registered. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity. A successful exploit could lead to a denial of service (kernel panic) but does not directly impact confidentiality or integrity. There is currently no evidence of active exploitation, nor is there any known exploit code available in public databases like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.3, < 4.19.316CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.278CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.219CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.161CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.93CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.