CVE-2024-47728 is a vulnerability in the Linux kernel's BPF subsystem that could lead to information leakage. Specifically, it involves the failure to zero out certain BPF argument values on error paths, potentially exposing kernel memory. This vulnerability is rated Medium severity (CVSS 5.5) with a local attack vector, low attack complexity, and a potential impact of high availability loss, though confidentiality and integrity are not directly affected. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2, < 6.1.113CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.54CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.10.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.11, < 6.11.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025CVE-2024-47728
Nov 12, 2024kernel: bpf: Zero former ARG_PTR_TO_{LONG,INT} args in case of error
Oct 21, 2024bpf: Zero former ARG_PTR_TO_{LONGINT} args in case of error
Oct 8, 2024