PT-2024-33812 · Linux+4 · Linux Kernel+4
Srinivasan Shanmugam
·
Published
2024-07-19
·
Updated
2026-05-26
·
CVE-2024-49970
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A buffer overflow error has been resolved in the Linux kernel, specifically in the
dcn401 stream encoder create function. The issue arises from an out-of-bounds access on the stream enc regs array, which is initialized with four elements and has valid indices of 0, 1, 2, and 3. If the eng id is used as an index and is set to 5, it results in an out-of-bounds access, leading to undefined behavior. The error was found by smatch in the dcn401 resource.c file.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Linux Kernel
Ubuntu