CVE-2024-42156

Updated: 2025-08-20 01:51:43.844392

Description:

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of clear-key structures on failure Wipe all sensitive data from stack for all IOCTLs, which convert a clear-key into a protected- or secure-key.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 4.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 4.1 MEDIUM Ignored 2024-08-05 05:25:51 This flaw is limited to the s390 pkey subsystem on IBM Z hardware, so x86_64 and ARM deployments are...
CentOS 8.4 ELS kernel 4.18.0 4.1 MEDIUM Ignored 2024-08-05 05:25:51 Ignored due to low severity
CentOS 8.5 ELS kernel 4.18.0 4.1 MEDIUM Ignored 2024-08-05 05:25:51 Ignored due to low severity
CentOS Stream 8 ELS kernel 4.18.0 4.1 MEDIUM Ignored 2024-08-05 05:25:51 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 4.1 MEDIUM Released CLSA-2024:1723622106 2024-08-14 08:18:41
Ubuntu 16.04 ELS linux 4.4.0 4.1 MEDIUM Not Vulnerable 2025-01-08 23:38:56
Ubuntu 18.04 ELS linux 4.15.0 4.1 MEDIUM Released CLSA-2024:1723622576 2024-08-14 08:18:36