LiveActive security incident?Get immediate response
CVE Record

CVE-2024-42155: s390/pkey: Wipe copies of protected- and secure-keys

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-keys Although the clear-key of neither protected- nor secure-keys is accessible, this key material should only be visible to the calling process. So wipe all copies of protected- or secure-keys from stack, even in case of an error.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue affects IBM s390 systems using protected or secure key handling. The bug left copies of sensitive key material on the kernel stack instead of wiping them in all paths, including errors. The source does not provide CVSS, confirmed exploitation, or distribution-specific fixed package names.

Executive priority

Treat this as a targeted kernel confidentiality issue for s390 environments, not a broad internet-facing emergency. Prioritize regulated or cryptographic workloads where protected or secure keys are used.

Technical view

The s390 pkey code failed to clear stack copies of protected-key or secure-key material. Although clear keys were not exposed, kernel stack copies should remain visible only to the calling process. The upstream fix wipes those copies consistently, including error handling paths.

Likely exposure

Exposure appears limited to Linux kernel deployments on s390 architecture that use the pkey protected-key or secure-key functionality. General Linux systems on other architectures are not indicated by the source bundle.

Exploitation context

The CVE is not listed as KEV in the provided bundle, and no cited source states active exploitation. The available evidence describes a confidentiality hardening fix rather than a public exploit scenario.

Researcher notes

The source does not name a CWE, CVSS vector, exploitability conditions, or affected downstream packages. Analysis should stay close to the upstream fix: stack copies of protected and secure keys are now wiped on success and error paths.

Mitigation direction

  • Check Linux distribution advisories for kernels containing the upstream stable fixes.
  • Update affected s390 Linux kernels through normal vendor-supported channels.
  • Prioritize systems using pkey protected-key or secure-key operations.
  • Review vendor guidance before applying compensating controls or deployment-specific mitigations.

Validation and detection

  • Inventory Linux systems running on s390 architecture.
  • Confirm kernel versions against vendor fixed-package guidance or the referenced stable commits.
  • Identify workloads using protected-key or secure-key pkey functionality.
  • Verify patched kernels are deployed and active after reboot.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-42155 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxe80d4af0a320972aac58e2004d0ba4e44ef4c5c7, e80d4af0a320972aac58e2004d0ba4e44ef4c5c7unaffected
LinuxLinux4.11, 0, 6.9.9, 6.10affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.