CVE-2024-36957
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace We try to access count + 1 byte from userspace with memdup_user(buffer, count + 1).
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace We try to access count + 1 byte from userspace with memdup_user(buffer, count + 1). However, the userspace only provides buffer of count bytes and only these count bytes are verified to be okay to access. To ensure the copied buffer is NUL terminated, we use memdup_user_nul instead.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-193
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0a0285cee11c7dcc2657bcd456e469958a5009e7Patch
- https://git.kernel.org/stable/c/8f11fe3ea3fc261640cfc8a5addd838000407c67Patch
- https://git.kernel.org/stable/c/bcdac70adceb44373da204c3c297f2a98e13216ePatch
- https://git.kernel.org/stable/c/ec697fbd38cbe2eef0948b58673b146caa95402fPatch
- https://git.kernel.org/stable/c/f299ee709fb45036454ca11e90cb2810fe771878Patch
- https://git.kernel.org/stable/c/fc3e0076c1f82fe981d321e3a7bad4cbee542c19Patch
- https://git.kernel.org/stable/c/0a0285cee11c7dcc2657bcd456e469958a5009e7Patch
- https://git.kernel.org/stable/c/8f11fe3ea3fc261640cfc8a5addd838000407c67Patch
- https://git.kernel.org/stable/c/bcdac70adceb44373da204c3c297f2a98e13216ePatch
- https://git.kernel.org/stable/c/ec697fbd38cbe2eef0948b58673b146caa95402fPatch
- https://git.kernel.org/stable/c/f299ee709fb45036454ca11e90cb2810fe771878Patch
- https://git.kernel.org/stable/c/fc3e0076c1f82fe981d321e3a7bad4cbee542c19Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00019.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.