PT-2024-28083 · Linux+5 · Linux Kernel+5

Dan Carpenter

+2

·

Published

2024-04-22

·

Updated

2025-02-08

·

CVE-2024-38621

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A buffer overflow issue has been resolved in the Linux kernel, specifically in the stk1160 copy video() function. The issue arises from a reversed subtraction condition, which results in an unsigned value that is always negative, leading to a very high positive value. This causes the overflow check to never be true. The ->bytesused variable does not work as intended for this purpose, and the math to calculate the destination where data is being written is complex. To fix this issue, the actual destination where data is being written is checked, and if the offset is out of bounds, an error is printed and the function returns. Otherwise, data is written up to buf->length bytes.
Recommendations To resolve this issue, update to a version of the Linux kernel that includes the fix for the stk1160 copy video() function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04187
CVE-2024-38621
DLA-3840-1
DSA-5730-1
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1793
OESA-2024-1839
OESA-2024-1941
OESA-2025-1081
OESA-2025-1097
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6953-1
USN-6979-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1
USN-7029-1
USN-7069-1
USN-7069-2
USN-7110-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu