fou: fix initialization of grc

Summary

CVECVE-2024-46865
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-09-27 13:15:17 UTC
Updated2026-05-12 12:17:12 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.

Risk And Classification

Primary CVSS: v3.1 7.1 HIGH from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

EPSS: 0.000140000 probability, percentile 0.026040000 (date 2026-05-12)

Problem Types: CWE-908

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel 5.10.226 All All All
Operating System Linux Linux Kernel 5.15.167 All All All
Operating System Linux Linux Kernel 6.1.110 All All All
Operating System Linux Linux Kernel 6.10.10 All All All
Operating System Linux Linux Kernel 6.6.51 All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 231c235d2f7a66f018f172e26ffd47c363f244ef 392f6a97fcbecc64f0c00058b2db5bb0e4b8cc3e git Not specified
CNA Linux Linux affected 4494bccb52ffda22ce5a1163a776d970e6229e08 16ff0895283058b0f96d4fe277aa25ee096f0ea8 git Not specified
CNA Linux Linux affected d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3 5d537b8d900514509622ce92330b70d2e581d409 git Not specified
CNA Linux Linux affected 1df42be305fe478ded1ee0c1d775f4ece713483b 7ae890ee19479eeeb87724cca8430b5cb3660c74 git Not specified
CNA Linux Linux affected c46cd6aaca81040deaea3500ba75126963294bd9 aca06c617c83295f0caa486ad608fbef7bdc11e8 git Not specified
CNA Linux Linux affected 7e4196935069947d8b70b09c1660b67b067e75cb 4c8002277167125078e6b9b90137bdf443ebaa08 git Not specified
CNA Linux Linux affected 5.10.226 5.10.227 semver Not specified
CNA Linux Linux affected 5.15.167 5.15.168 semver Not specified
CNA Linux Linux affected 6.1.110 6.1.111 semver Not specified
CNA Linux Linux affected 6.6.51 6.6.52 semver Not specified
CNA Linux Linux affected 6.10.10 6.10.11 semver Not specified
ADP Siemens SIMATIC S7-1500 TM MFP - GNU/Linux Subsystem affected * custom Not specified

References

ReferenceSourceLinkTags
lists.debian.org/debian-lts-announce/2025/03/msg00002.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org
git.kernel.org/stable/c/392f6a97fcbecc64f0c00058b2db5bb0e4b8cc3e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4c8002277167125078e6b9b90137bdf443ebaa08 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/7ae890ee19479eeeb87724cca8430b5cb3660c74 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
cert-portal.siemens.com/productcert/html/ssa-265688.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/16ff0895283058b0f96d4fe277aa25ee096f0ea8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5d537b8d900514509622ce92330b70d2e581d409 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/aca06c617c83295f0caa486ad608fbef7bdc11e8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2025/01/msg00001.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report