PT-2024-7061 · Linux+6 · Linux Kernel+6

Junhao He

·

Published

2024-04-28

·

Updated

2025-09-29

·

CVE-2024-38568

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an out-of-bound access in the hns3 pmu validate event group() function in the Linux kernel. This occurs when the perf tool is used to create event groups, and the driver does not check if the array index is out of bounds when writing data to the event group array. If the number of events in an event group exceeds HNS3 PMU MAX HW EVENTS, a memory write overflow of the event group array can happen. The vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The perf stat command with the -e option can be used to create event groups, for example, perf stat -e '{pmu/event1/, ... ,pmu/event9/}'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2024-08319
CVE-2024-38568
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1894
OESA-2024-1896
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu