VulnerabilityModified
CVE-2024-26664
In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check.
HIGH 7.1EPSS 0.25%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem might be triggered on systems with more than 128 cores per package.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8bPatch
- https://git.kernel.org/stable/c/3a7753bda55985dc26fae17795cb10d825453ad1Patch
- https://git.kernel.org/stable/c/4e440abc894585a34c2904a32cd54af1742311b3Patch
- https://git.kernel.org/stable/c/853a6503c586a71abf27e60a7f8c4fb28092976dPatch
- https://git.kernel.org/stable/c/93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6aPatch
- https://git.kernel.org/stable/c/9bce69419271eb8b2b3ab467387cb59c99d80debPatch
- https://git.kernel.org/stable/c/a16afec8e83c56b14a4a73d2e3fb8eec3a8a057ePatch
- https://git.kernel.org/stable/c/f0da068c75c20ffc5ba28243ff577531dc2af1fdPatch
- https://git.kernel.org/stable/c/1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8bPatch
- https://git.kernel.org/stable/c/3a7753bda55985dc26fae17795cb10d825453ad1Patch
- https://git.kernel.org/stable/c/4e440abc894585a34c2904a32cd54af1742311b3Patch
- https://git.kernel.org/stable/c/853a6503c586a71abf27e60a7f8c4fb28092976dPatch
- https://git.kernel.org/stable/c/93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6aPatch
- https://git.kernel.org/stable/c/9bce69419271eb8b2b3ab467387cb59c99d80debPatch
- https://git.kernel.org/stable/c/a16afec8e83c56b14a4a73d2e3fb8eec3a8a057ePatch
- https://git.kernel.org/stable/c/f0da068c75c20ffc5ba28243ff577531dc2af1fdPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing List
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.