PT-2024-1991 · Linux+5 · Linux Kernel+5

Uwe Kleine-König

·

Published

2024-01-12

·

Updated

2024-10-02

·

CVE-2024-26599

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an out-of-bounds access in the of pwm single xlate() function of the Linux kernel's PWM (Pulse Width Modulation) driver. This can potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information. The problem occurs when args->args count equals 2, and args->args[2] is not defined, while the flags are actually contained in args->args[1].
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01835
CVE-2024-26599
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
USN-6688-1
USN-6707-1
USN-6707-2
USN-6707-3
USN-6707-4

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu