CVE-2024-42312 - CVE House
Back to Database
Status published Unknown CVE-2024-42312

sysctl: always initialize i_uid/i_gid

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: sysctl: always initialize i_uid/i_gid Always initialize i_uid/i_gid inside the sysfs core so set_ownership() can safely skip setting them. Commit 5ec27ec735ba ("fs/proc/proc_sysctl.c: fix the default values of i_uid/i_gid on /proc/sys inodes.") added defaults for i_uid/i_gid when set_ownership() was not implemented. It also missed adjusting net_ctl_set_ownership() to use the same default values in case the computation of a better value failed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-42312

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
5ec27ec735ba0477d48c80561cc5e856f0c5dfaf, e83234d7ef237931148b4b17834dadf57eb46c12, 2cbf2af144f0cd08a3361c6299b2e6086b7d21d9, 2c7b50c7b1d036f71acd9a917a8cb0f9b6e43dab, 7eb45a94c279dd5af4cafaa738ae93737517eef4, 14cc90952cef94bfa89a6b4a2f55fd9a70f50a16, 4.9.187, 4.14.135, 4.19.61, 5.1.20, 5.2.3, 5.3, 0, 5.10.224, 5.15.165, 6.1.104, 6.6.45, 6.10.3, 6.11

Timeline

Official Publish: August 17th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.