CVE-2024-36288
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jun 21, 2024
Updated: Jul 15, 2024
CWE ID 835
Summary
CVE-2024-36288: A vulnerability in the Linux kernel's SUNRPC subsystem has been addressed. The issue lies in a failure to properly terminate the in_token->pages[] array in gss_free_in_token_pages(), leading to a KASAN memory error and potential wild-access memory issue within the range [0x04a2013400000008-0x04a201340000000f].
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.