CVE-2024-26730
In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers. This can result in access errors reported if KASAN is enabled. BUG: KASAN: global-out-of-bounds in nct6775_probe+0x5654/0x6fe9 nct6775_core
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/745aa03c513f1ba12cb98495467676f7acf3fffd
- https://git.kernel.org/stable/c/c196387820c9214c5ceaff56d77303c82514b8b1Patch
- https://git.kernel.org/stable/c/d56e460e19ea8382f813eb489730248ec8d7eb73Patch
- https://git.kernel.org/stable/c/f006c45a3ea424f8f6c8e4b9283bc245ce2a4d0fPatch
- https://git.kernel.org/stable/c/c196387820c9214c5ceaff56d77303c82514b8b1Patch
- https://git.kernel.org/stable/c/d56e460e19ea8382f813eb489730248ec8d7eb73Patch
- https://git.kernel.org/stable/c/f006c45a3ea424f8f6c8e4b9283bc245ce2a4d0fPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.