Linux Security Updates – 25 February 2024

Linux has released security updates to address several vulnerabilities in Linux Kernel.

The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system.

Sample of the addressed vulnerabilities:

1. Linux Kernel Information Disclosure Vulnerability (CVE-2024-26594):

  • CVSS: 9.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

2. Linux Kernel Code Execution Vulnerability (CVE-2024-26592):

  • CVSS: 9
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
Mitigations

The enterprise should deploy the patches as soon as the testing phase is completed and should check with its vendors for updates if any.

Below is a sample of the distributors’ fixes:

References