CVE-2024-53106·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: ima: fix buffer overrun in ima_eventdigest_init_common Function ima_eventdigest_init() calls ima_eventdigest_init_common() with HASH_ALGO__LAST which is then used to access the array hash_digest_size[] leading to buffer overrun. Have a conditional statement to handle this.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.10
- Published
- 2024-12-02
Affected versions
From: 6.7
Until: 6.11.10
Fixed in: 6.11.10
How to fix this CVE
Update your Linux kernel to version 6.11.10 or later to patch a buffer overrun vulnerability in the IMA (Integrity Measurement Architecture) subsystem. This flaw allows local authenticated users with low privileges to trigger memory corruption by passing invalid hash algorithm identifiers to kernel functions. Affected systems running kernel versions 6.7 through 6.11.9 should prioritize this update to prevent potential denial of service or privilege escalation attacks.
sudo dnf update kernel kernel-headers kernel-develDefensia detects this vulnerability
How to check if you are affected
- Run 'uname -r' to check your current kernel version and confirm if it falls within the vulnerable range (6.7 to 6.11.9)
- Verify IMA is enabled on your system by checking 'cat /proc/cmdline | grep ima_policy' or 'grep CONFIG_IMA /boot/config-$(uname -r)'
- Search kernel logs for IMA-related errors using 'grep -i ima /var/log/kern.log' or 'journalctl -k | grep -i ima' to identify any buffer overrun warnings
- After updating, run 'uname -r' again to confirm the kernel has been upgraded to 6.11.10 or later, then reboot if necessary
FAQ
What is CVE-2024-53106?
CVE-2024-53106 is a buffer overrun vulnerability in the Linux kernel's IMA (Integrity Measurement Architecture) event digest initialization function. The flaw occurs when an invalid hash algorithm identifier is passed to the kernel, causing it to access memory beyond the bounds of the hash_digest_size array, potentially leading to information disclosure or system instability.
Is CVE-2024-53106 being actively exploited?
No, CVE-2024-53106 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available. However, the vulnerability requires local authentication and should still be patched promptly as a best practice.
What versions of Kernel are affected by CVE-2024-53106?
Linux kernel versions 6.7 through 6.11.9 are affected. The vulnerability has been fixed in kernel version 6.11.10 and later.
How do I check if my server is vulnerable to CVE-2024-53106?
Run 'uname -r' to display your kernel version. If it shows a version between 6.7 and 6.11.9, your system is vulnerable. Cross-reference the version number with the fixed release 6.11.10.
Does Defensia detect CVE-2024-53106?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-53106 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/1ecf0df5205cfb0907eb7984b8671257965a5232
- https://git.kernel.org/stable/c/8a84765c62cc0469864e2faee43aae253ad16082
- https://git.kernel.org/stable/c/923168a0631bc42fffd55087b337b1b6c54dcff5
- https://git.kernel.org/stable/c/e01aae58e818503f2ffcd34c6f7dc6f90af1057e
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-53106. Free for 1 server.
Get started free