CVE-2024-57910: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iio: light: vcnl4035: fix information leak in triggered buffer The 'buffer' local array is used to push data to userspace from a triggered buffer, but it does not set an initial value for the single data element, which is an u16 aligned to 8 bytes. That leaves at least 4 bytes uninitialized even after writing an integer value with regmap_read(). Initialize the array to zero before using it to avoid pushing uninitialized information to userspace.

Affected products

  • Linux Linux Kernel: from 5.4.132, before 5.4.290 (fixed in 5.4.290); from 5.10.50, before 5.10.234 (fixed in 5.10.234); from 5.12.17, before 5.13 (fixed in 5.13); from 5.13.2, before 5.15.177 (fixed in 5.15.177); from 5.16, before 6.1.125 (fixed in 6.1.125); from 6.2, before 6.6.72 (fixed in 6.6.72); …

Published 2025-01-19. Last modified 2026-06-17.