PT-2024-28504 · Linux+5 · Linux Kernel+5

Published

2024-04-25

·

Updated

2025-09-29

·

CVE-2024-39461

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel, where the ->num initialization is moved to before the first access of ->hws to clear up a warning. This warning occurs because the counted by member must be initialized with the number of elements before the first array access happens. The problem is in the raspberrypi discover clocks() function, where ->num is assigned after ->hws has been accessed, resulting in an array-index-out-of-bounds error.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
BDU:2025-03450
CVE-2024-39461
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1836
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu