PT-2024-10034 · Linux+7 · Linux Kernel+7

Andrey Shumilin

·

Published

2024-09-28

·

Updated

2025-10-03

·

CVE-2024-50180

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a buffer overflow in the sisfb function of the Linux kernel. The variables xres and yres are obtained from strbuf1 and placed in strbuf. When executing sprintf(strbuf, "%ux%ux8", xres, yres), more than 16 bytes will be written to strbuf, causing an overflow. It is suggested to increase the size of the strbuf array to 24. The vulnerability may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations To resolve the issue, it is recommended to increase the size of the strbuf array to 24. As a temporary workaround, consider restricting the use of the sisfb function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-14270
ALT-PU-2024-16172
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-53670
BDU:2025-00170
CVE-2024-50180
DLA-4008-1
DLA-4075-1
OESA-2024-2446
OESA-2024-2491
OESA-2024-2493
OESA-2024-2494
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1
USN-7276-1
USN-7277-1
USN-7293-1
USN-7294-1
USN-7294-2
USN-7294-3
USN-7294-4
USN-7295-1
USN-7310-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7393-1
USN-7401-1
USN-7403-1
USN-7413-1
USN-7451-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7539-1
USN-7540-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu