CVE-2024-27388: SUNRPC: fix some memleaks in gssx_dec_option_array
Published May 1, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
23 affected componentsFixes available
Linux Linux kernel>=3.10<4.19.311
Linux Linux kernel>=4.20<5.4.273
Linux Linux kernel>=5.5<5.10.214
Linux Linux kernel>=5.11<5.15.153
Linux Linux kernel>=5.16<6.1.83
Linux Linux kernel>=6.2<6.6.23
Linux Linux kernel>=6.7<6.7.11
Linux Linux kernel>=6.8<6.8.2
Debian Debian Linux=10.0
IBM Security Verify Governance<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Software Stack<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Virtual Appliance<=ISVG 10.0.2
IBM Security Verify Governance Identity Manager Container<=ISVG 10.0.2
redhat/kernel<4.19.311
4.19.311
redhat/kernel<5.4.273
5.4.273
redhat/kernel<5.10.214
5.10.214
redhat/kernel<5.15.153
5.15.153
redhat/kernel<6.1.83
6.1.83
redhat/kernel<6.6.23
6.6.23
redhat/kernel<6.7.11
6.7.11
redhat/kernel<6.8.2
6.8.2
redhat/kernel<6.9
6.9
debian/linux
5.10.223-15.10.251-56.1.170-36.1.172-16.12.86-16.12.88-17.0.7-1
Remediation
Event History
May 1, 2024
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
Description
Data Sourced
via Red Hat·09:50 PM
DescriptionSeverityAffected Software
May 19, 2026
Data Sourced
via Ubuntu·09:35 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:35 AM
DescriptionAffected Software
Data Sourced
via Launchpad·09:35 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-27388?
CVE-2024-27388 is classified as a moderate severity vulnerability due to potential memory leaks in the Linux kernel.
2
How do I fix CVE-2024-27388?
To fix CVE-2024-27388, update your Linux kernel to versions 4.19.311, 5.4.273, 5.10.214, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, or 6.9.
3
What software is affected by CVE-2024-27388?
CVE-2024-27388 affects multiple versions of the Linux kernel, particularly those below version 4.19.311.
4
Is CVE-2024-27388 remotely exploitable?
CVE-2024-27388 is not classified as remotely exploitable but can pose risks in local or multi-tenant environments.
5
What components are impacted by CVE-2024-27388?
CVE-2024-27388 impacts the SUNRPC (Sun Remote Procedure Call) component within the Linux kernel.