CVE-2024-36288 - CVE House
Back to Database
Status published Unknown CVE-2024-36288

SUNRPC: Fix loop termination condition in gss_free_in_token_pages()

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory-access in range [0x04a2013400000008-0x04a201340000000f]

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-36288

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
ab8466d4e26806a4ae82c282762c4545eecf45ef, 4420b73c7f26fd5fcb37bbce5313dd356ef1b3ca, f148a95f68c66c1b097391b68e153d5a46f0e780, fe0b474974fee7af1df286e0edd5a1460c811865, c1d8c429e4d2ce85ec5c92cf71cb419baf75c56f, 8ca148915670a2921afcc255af9e1dc80f37b052, bafa6b4d95d97877baa61883ff90f7e374427fae, a3c1afd5d7ad59e34a275d80c428952f83c8c1f0, 6.8.12, 6.9.3

Timeline

Official Publish: June 21st, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.