CVE-2024-26965 — Out-of-bounds Write in Linux
Severity
7.8HIGHNVD
OSV7.0OSV5.5
EPSS
0.0%
top 96.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays
The frequency table arrays are supposed to be terminated with an
empty element. Add such entry to the end of the arrays where it
is missing in order to avoid possible out-of-bound access when
the table is traversed by functions like qcom_find_freq() or
qcom_find_freq_floor().
Only compile tested.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages13 packages
▶CVEListV5linux/linuxd8b212014e69d6b6323773ce6898f224ef4ed0d6 — 99740c4791dc8019b0d758c5389ca6d1c0604d95+9
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
20📋Vendor Advisories
21💬Community
1Bugzilla▶
CVE-2024-26965 kernel: clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays↗2024-05-01