CVE-2024-35823
In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when…
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting chars in the buffer"). The cure is also the same i.e. replace memcpy() with memmove() due to the overlaping buffers.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0190d19d7651c08abc187dac3819c61b726e7e3fPatch
- https://git.kernel.org/stable/c/1581dafaf0d34bc9c428a794a22110d7046d186dPatch
- https://git.kernel.org/stable/c/1ce408f75ccf1e25b3fddef75cca878b55f2ac90Patch
- https://git.kernel.org/stable/c/2933b1e4757a0a5c689cf48d80b1a2a85f237ff1Patch
- https://git.kernel.org/stable/c/7529cbd8b5f6697b369803fe1533612c039cabdaPatch
- https://git.kernel.org/stable/c/994a1e583c0c206c8ca7d03334a65b79f4d8bc51Patch
- https://git.kernel.org/stable/c/fc7dfe3d123f00e720be80b920da287810a1f37dPatch
- https://git.kernel.org/stable/c/ff7342090c1e8c5a37015c89822a68b275b46f8aPatch
- https://git.kernel.org/stable/c/0190d19d7651c08abc187dac3819c61b726e7e3fPatch
- https://git.kernel.org/stable/c/1581dafaf0d34bc9c428a794a22110d7046d186dPatch
- https://git.kernel.org/stable/c/1ce408f75ccf1e25b3fddef75cca878b55f2ac90Patch
- https://git.kernel.org/stable/c/2933b1e4757a0a5c689cf48d80b1a2a85f237ff1Patch
- https://git.kernel.org/stable/c/7529cbd8b5f6697b369803fe1533612c039cabdaPatch
- https://git.kernel.org/stable/c/994a1e583c0c206c8ca7d03334a65b79f4d8bc51Patch
- https://git.kernel.org/stable/c/fc7dfe3d123f00e720be80b920da287810a1f37dPatch
- https://git.kernel.org/stable/c/ff7342090c1e8c5a37015c89822a68b275b46f8aPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlMailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.