CVE-2024-57930 is a Linux kernel vulnerability related to the tracing subsystem, specifically concerning how string references are handled in trace events. The vulnerability arises from an overly aggressive check in the process_string() function, which incorrectly flagged legitimate array-indexed string references as unsafe. This issue affects Linux kernel versions where this tracing logic is present. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity and low privileges required. The potential impact is a high availability impact, meaning it could lead to system instability or crashes, but does not directly compromise confidentiality or integrity. There is no evidence of active exploitation for CVE-2024-57930. No public exploit code or Metasploit modules are available, and there is no significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.122, < 6.1.124CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.6.68, < 6.6.70CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.12.7, < 6.12.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:rc4:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:rc5:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.