{"id":"DEBIAN-CVE-2024-42161","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD  [Changes from V1:  - Use a default branch in the switch statement to initialize `val'.]  GCC warns that `val' may be used uninitialized in the BPF_CRE_READ_BITFIELD macro, defined in bpf_core_read.h as:  \t[...] \tunsigned long long val;\t\t\t\t\t\t      \\ \t[...]\t\t\t\t\t\t\t\t      \\ \tswitch (__CORE_RELO(s, field, BYTE_SIZE)) {\t\t\t      \\ \tcase 1: val = *(const unsigned char *)p; break;\t\t\t      \\ \tcase 2: val = *(const unsigned short *)p; break;\t\t      \\ \tcase 4: val = *(const unsigned int *)p; break;\t\t\t      \\ \tcase 8: val = *(const unsigned long long *)p; break;\t\t      \\         }       \t\t\t\t\t\t\t      \\ \t[...] \tval;\t\t\t\t\t\t\t\t      \\ \t}\t\t\t\t\t\t\t\t      \\  This patch adds a default entry in the switch statement that sets `val' to zero in order to avoid the warning, and random values to be used in case __builtin_preserve_field_info returns unexpected values for BPF_FIELD_BYTE_SIZE.  Tested in bpf-next master. No regressions.","modified":"2026-09-15T09:03:10.122254230Z","published":"2024-07-30T08:15:07.447Z","upstream":["CVE-2024-42161"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-42161"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.98-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42161.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.9.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42161.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.9.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42161.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H"}]}