PT-2024-27216 · Linux+4 · Linux Kernel+4

Bui Quang Minh

·

Published

2024-04-25

·

Updated

2025-02-03

·

CVE-2024-36935

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises from the allocation of a count-sized kernel buffer and copying count bytes from userspace to that buffer. Later, sscanf is used on this buffer without ensuring the string is terminated inside the buffer, leading to an out-of-bounds (OOB) read when using sscanf. This is fixed by using memdup user nul instead of memdup user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07243
CVE-2024-36935
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu