CVE-2024-38541·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: of: module: add buffer overflow check in of_modalias() In of_modalias(), if the buffer happens to be too small even for the 1st snprintf() call, the len parameter will become negative and str parameter (if not NULL initially) will point beyond the buffer's end. Add the buffer overflow check after the 1st snprintf() call and fix such check after the strlen() call (accounting for the terminating NUL char).
- Severity
- critical
- Software
- Kernel
- Fixed in
- 6.9.3
- Published
- 2024-06-19
Affected versions
From: 6.9
Until: 6.9.3
Fixed in: 6.9.3
How to fix this CVE
Update your Linux kernel to version 6.9.3 or later to patch a critical buffer overflow vulnerability in the device tree modalias function. Systems running kernel versions 6.9 through 6.9.2 should prioritize this update immediately, as the flaw can lead to memory corruption and potential privilege escalation. Apply the patch through your distribution's standard kernel update mechanism.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version: uname -r — vulnerable versions are 6.9.0, 6.9.1, and 6.9.2
- Verify the of_modalias function is compiled in your kernel: grep -i modalias /boot/config-$(uname -r) — look for CONFIG_OF_DYNAMIC=y
- Monitor kernel logs for memory errors: dmesg | grep -i 'buffer\|overflow\|fault' — exploitation may cause kernel panic or warning messages
- Confirm patch application after update: uname -r should show 6.9.3 or later
FAQ
What is CVE-2024-38541?
This is a buffer overflow vulnerability in the Linux kernel's device tree handling code. When the of_modalias() function receives a buffer that is too small, it can write beyond allocated memory boundaries, potentially leading to kernel memory corruption and privilege escalation attacks.
Is CVE-2024-38541 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits have been disclosed, though the critical CVSS score of 9.8 warrants immediate patching.
What versions of Kernel are affected by CVE-2024-38541?
Linux kernel versions 6.9.0 through 6.9.2 are affected. Version 6.9.3 and later include the fix. Earlier kernel branches (6.8 and below) are not impacted.
How do I check if my server is vulnerable to CVE-2024-38541?
Run `uname -r` and check if the output shows 6.9.0, 6.9.1, or 6.9.2. If your kernel version is 6.9.3 or higher, or uses a different major version series, you are not vulnerable.
Does Defensia detect CVE-2024-38541?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-38541 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0b0d5701a8bf02f8fee037e81aacf6746558bfd6
- https://git.kernel.org/stable/c/46795440ef2b4ac919d09310a69a404c5bc90a88
- https://git.kernel.org/stable/c/5d59fd637a8af42b211a92b2edb2474325b4d488
- https://git.kernel.org/stable/c/733e62786bdf1b2b9dbb09ba2246313306503414
- https://git.kernel.org/stable/c/c7f24b7d94549ff4623e8f41ea4d9f5319bd8ac8
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-38541. Free for 1 server.
Get started free