cbcvebase.
CVE-2024-26876
published 2024-04-17

CVE-2024-26876: In the Linux kernel, the following vulnerability has been resolved: drm/bridge: adv7511: fix crash on irq during probe Moved IRQ registration down to end of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: adv7511: fix crash on irq during probe Moved IRQ registration down to end of adv7511_probe(). If an IRQ already is pending during adv7511_probe (before adv7511_cec_init) then cec_received_msg_ts could crash using uninitialized data: Unable to handle kernel read from unreadable memory at virtual address 00000000000003d5 Internal error: Oops: 96000004 [#1] PREEMPT_RT SMP Call trace: cec_received_msg_ts+0x48/0x990 [cec] adv7511_cec_irq_process+0x1cc/0x308 [adv7511] adv7511_irq_process+0xd8/0x120 [adv7511] adv7511_irq_handler+0x1c/0x30 [adv7511] irq_thread_fn+0x30/0xa0 irq_thread+0x14c/0x238 kthread+0x190/0x1a8

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= 3b1b975003e4a3da4b93ab032487a3ae4afca7b5 < 50f4b57e9a9db4ede9294f39b9e75b5f26bae9b750f4b57e9a9db4ede9294f39b9e75b5f26bae9b7
linuxlinux>= 3b1b975003e4a3da4b93ab032487a3ae4afca7b5 < 955c1252930677762e0db2b6b9e36938c887445c955c1252930677762e0db2b6b9e36938c887445c
linuxlinux>= 3b1b975003e4a3da4b93ab032487a3ae4afca7b5 < 28a94271bd50e4cf498df0381f776f8ea40a289e28a94271bd50e4cf498df0381f776f8ea40a289e
linuxlinux>= 3b1b975003e4a3da4b93ab032487a3ae4afca7b5 < aeedaee5ef5468caf59e2bb1265c2116e0c9a924aeedaee5ef5468caf59e2bb1265c2116e0c9a924
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.15 < 6.6.556.6.55
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.