PT-2024-7285 · Linux+1 · Linux Kernel+1

Erhard Furtner

·

Published

2024-02-21

·

Updated

2024-10-22

·

CVE-2024-26730

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the nct6775 component of the Linux kernel, which is associated with errors reading beyond the buffer boundaries. This can result in access errors being reported if KASAN is enabled. The problem arises because the number of temperature configuration registers does not always match the total number of temperature registers. There is a global-out-of-bounds error in the nct6775 probe function.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-08639
CVE-2024-26730

Affected Products

Linux Kernel
Red Os