PT-2024-7042 · Linux+5 · Linux Kernel+5

Chenyuan Yang

·

Published

2024-05-27

·

Updated

2025-09-29

·

CVE-2024-43825

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the sorting functionality in the iio gts build avail time table function, which is not working as intended. This could result in an out-of-bounds access when the time is zero. Specifically, when gts->itime table[i].time us is zero, the inner for-loop may not terminate and perform out-of-bound writes. If none of the gts->itime table[i].time us values are zero, the elements will be copied without being sorted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
BDU:2024-08300
CVE-2024-43825
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2124
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu