PT-2024-33812 · Linux+4 · Linux Kernel+4

Srinivasan Shanmugam

·

Published

2024-07-19

·

Updated

2026-05-26

·

CVE-2024-49970

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A buffer overflow error has been resolved in the Linux kernel, specifically in the dcn401 stream encoder create function. The issue arises from an out-of-bounds access on the stream enc regs array, which is initialized with four elements and has valid indices of 0, 1, 2, and 3. If the eng id is used as an index and is set to 5, it results in an out-of-bounds access, leading to undefined behavior. The error was found by smatch in the dcn401 resource.c file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-51850
AZL-51852
BDU:2025-16133
CVE-2024-49970
ECHO-1246-E70D-B667
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Ubuntu