Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
crypto: caam - use print_hex_dump_devel to guard key hex dumps
Use print_hex_dump_devel() for dumping sensitive key material in *_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG is enabled.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Amazon Linux 2 ELS , Debian 11 ELS , Oracle Linux 7 ELS , TuxCare 9.6 ESU , TuxCare 9.8 ESU , Ubuntu 20.04 ELS
- Affected packages:
- linux @ 5.4.0 (+6 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 11 | Will Not Fix |
44 kernels
|
| Debian 11 cloud | Will Not Fix |
24 kernels
|
| Debian 12 | Will Not Fix |
42 kernels
|