cbcvebase.
CVE-2024-26599
published 2024-02-23

CVE-2024-26599: In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlate() With args->args_count == 2…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.5th percentile
In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlate() With args->args_count == 2 args->args[2] is not defined. Actually the flags are contained in args->args[1].

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 3ab7b6ac5d829e60c3b89d415811ff1c9f358c8e < 7b85554c7c2aee91171e038e4d5442ffa130b2827b85554c7c2aee91171e038e4d5442ffa130b282
linuxlinux>= 3ab7b6ac5d829e60c3b89d415811ff1c9f358c8e < e5f2b4b62977fb6c2efcbc5779e0c9dce18215f7e5f2b4b62977fb6c2efcbc5779e0c9dce18215f7
linuxlinux>= 3ab7b6ac5d829e60c3b89d415811ff1c9f358c8e < bae45b7ebb31984b63b13c3519fd724b3ce92123bae45b7ebb31984b63b13c3519fd724b3ce92123
linuxlinux>= 3ab7b6ac5d829e60c3b89d415811ff1c9f358c8e < a297d07b9a1e4fb8cda25a4a2363a507d294b7c9a297d07b9a1e4fb8cda25a4a2363a507d294b7c9
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 5.17 < 6.1.756.1.75
linuxlinux_kernel>= 6.2.0 < 6.6.146.6.14
linuxlinux_kernel>= 6.7.0 < 6.7.26.7.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.