In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: Do not use WARN when encode fails
When asn1_encode_sequence() fails, WARN is not the correct solution.
1. asn1_encode_sequence() is not an internal function (located
in lib/asn1_encode.c).
2. Location is known, which makes the stack trace useless.
3. Results a crash if panic_on_warn is set.
It is also noteworthy that the use of WARN is undocumented, and it
should be avoided unless there is a carefully considered rationale to
use it.
Replace WARN with pr_err, and print the return value instead, which is
only useful piece of information.
References
Configurations
Configuration 1 (hide)
|
History
01 Oct 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| First Time |
Linux linux Kernel
Linux |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| References | () https://git.kernel.org/stable/c/050bf3c793a07f96bd1e2fd62e1447f731ed733b - Patch | |
| References | () https://git.kernel.org/stable/c/1c652e1e10676f942149052d9329b8bf2703529a - Patch | |
| References | () https://git.kernel.org/stable/c/681935009fec3fc22af97ee312d4a24ccf3cf087 - Patch | |
| References | () https://git.kernel.org/stable/c/96f650995c70237b061b497c66755e32908f8972 - Patch | |
| References | () https://git.kernel.org/stable/c/d32c6e09f7c4bec3ebc4941323f0aa6366bc1487 - Patch | |
| References | () https://git.kernel.org/stable/c/ff91cc12faf798f573dab2abc976c1d5b1862fea - Patch |
21 Nov 2024, 09:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/050bf3c793a07f96bd1e2fd62e1447f731ed733b - | |
| References | () https://git.kernel.org/stable/c/1c652e1e10676f942149052d9329b8bf2703529a - | |
| References | () https://git.kernel.org/stable/c/681935009fec3fc22af97ee312d4a24ccf3cf087 - | |
| References | () https://git.kernel.org/stable/c/96f650995c70237b061b497c66755e32908f8972 - | |
| References | () https://git.kernel.org/stable/c/d32c6e09f7c4bec3ebc4941323f0aa6366bc1487 - | |
| References | () https://git.kernel.org/stable/c/ff91cc12faf798f573dab2abc976c1d5b1862fea - |
20 Jun 2024, 12:44
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Jun 2024, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-06-18 20:15
Updated : 2025-10-01 15:16
NVD link : CVE-2024-36975
Mitre link : CVE-2024-36975
CVE.ORG link : CVE-2024-36975
JSON object : View
Products Affected
linux
- linux_kernel
CWE
