CVE-2024-39487: bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
bonding: Fix out-of-bounds read in bondoptionarpiptargetsset()
Other sources
Linux Kernel is vulnerable to a denial of service, caused by an out-of-bounds read in bondoptionarpiptargetsset(). A local authenticated attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39487?
CVE-2024-39487 has a medium severity rating due to the potential for an out-of-bounds read vulnerability.
How do I fix CVE-2024-39487?
To fix CVE-2024-39487, update the Linux kernel to version 6.10 or apply the respective patches as provided by your Linux distribution.
What versions of the Linux kernel are affected by CVE-2024-39487?
CVE-2024-39487 affects several versions of the Linux kernel including those between 3.13 and 6.9.9.
What issues does CVE-2024-39487 cause in the Linux kernel?
CVE-2024-39487 can lead to an out-of-bounds read which may result in reading sensitive data or causing application crashes.
Is CVE-2024-39487 a remote exploit?
CVE-2024-39487 is not a remote exploit but rather an issue that can be exploited locally within the affected system.