PT-2024-30734 · Linux+5 · Linux Kernel+5

Published

2024-05-31

·

Updated

2025-10-19

·

CVE-2024-43877

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel's media: pci: ivtv component, where a check for DMA map result was added to prevent out of bounds access. When DMA fails, dma->SG length is 0, and this value is later used to access dma->SGarray[dma->SG length - 1], causing the out of bounds access. A check was added to return early on invalid values, and warnings were adjusted accordingly. The issue was found by the Linux Verification Center with SVACE.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01931
CVE-2024-43877
DLA-4008-1
MGASA-2024-0309
MGASA-2024-0310
OESA-2025-1097
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu