kernel CVE-2024-23849
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.19.1
Patched versions
1.19.1
kernel-5.15
(bottlerocket)
< 1.19.2
1.19.2
kernel-6.1
(bottlerocket)
< 1.19.2
1.19.2
An out-of-bounds access flaw was found in the Linux kernel’s implementation of the reliable datagram sockets protocol. An off-by-one error in
rds_recv_track_latency
comparing against RDS_MSG_RX_DGRAM_TRACE_MAX results in out-of-bounds access.