CVE-2024-9042

unknown
Published 2025-03-13 · Modified 2026-02-04
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS v2
VIR risk

Description

This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-9042.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-9042

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
golang Gok8s.io/kubernetes<1.29.131.29.13
golang Gok8s.io/kubernetes>=1.30.0-alpha.0,<1.30.91.30.9
golang Gok8s.io/kubernetes>=1.31.0-alpha.0,<1.31.51.31.5
golang Gok8s.io/kubernetes>=1.32.0-alpha.0,<1.32.11.32.1

References

Verify integrity in audit chain (admin only). AS-IS.