CVE-2024-43845 describes an uninitialized memory access vulnerability in the Linux kernel's UDF filesystem, specifically within the udf_rename() function. This flaw, identified by Syzbot, occurs during the checksum computation of a moved directory's ".." entry, where random stack contents are incorrectly included. While the subsequent udf_fiiter_write_fi() function corrects the checksum, the initial computation is erroneous. The vulnerability has a CVSS score of 3.3 (Low severity), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in a low impact on integrity (CWE-908). There is no impact on confidentiality or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3, < 6.6.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.10.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.