CVE-2024-38381: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header size, payload size and total packet size before processing the packet. If an invalid packet is detected, it should be silently discarded.
Affected products
- Linux Linux Kernel: from 4.19.312, before 4.19.316 (fixed in 4.19.316); from 5.4.274, before 5.4.278 (fixed in 5.4.278); from 5.10.215, before 5.10.219 (fixed in 5.10.219); from 5.15.154, before 5.15.161 (fixed in 5.15.161); from 6.1.85, before 6.1.93 (fixed in 6.1.93); from 6.6.26, before 6.6.33 (fixed in 6.6.33); …
Published 2024-06-21. Last modified 2026-08-04.