CVE-2024-53142 addresses a filename buffer overrun in the Linux kernel's initramfs handling. Specifically, a specially crafted cpio entry with a non-zero-terminated filename could lead to the creation of files with trailing uninitialized memory characters. This vulnerability affects the Linux kernel. The CVSS score of 7.8 (High) indicates a significant impact, with local access required for exploitation (AV:L). While the vulnerability itself is not considered a direct security risk due to the prerequisite of system control to create an initramfs entry, it could lead to information disclosure (C:H) and integrity (I:H) issues by creating files with unexpected names. There is no evidence of active exploitation, nor are there any known public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.12, < 4.19.325CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 6.6.64CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.11.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.12, < 6.12.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025initramfs: avoid filename buffer overrun
Dec 10, 2024kernel: initramfs: avoid filename buffer overrun
Dec 6, 2024