CVE-2024-42229: Linux Kernel
Medium severity, CVSS 4.1. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: crypto: aead,cipher - zeroize key buffer after use I.G 9.7.B for FIPS 140-3 specifies that variables temporarily holding cryptographic information should be zeroized once they are no longer needed. Accomplish this by using kfree_sensitive for buffers that previously held the private key.
Affected products
- Linux Linux Kernel: before 5.10.222 (fixed in 5.10.222); from 5.11, before 5.15.163 (fixed in 5.15.163); from 5.16, before 6.1.98 (fixed in 6.1.98); from 6.2, before 6.6.39 (fixed in 6.6.39); from 6.7, before 6.9.9 (fixed in 6.9.9)
Published 2024-07-30. Last modified 2026-06-17.