cbcvebase.
CVE-2024-26966
published 2024-05-01

CVE-2024-26966: In the Linux kernel, the following vulnerability has been resolved: clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays The frequency table…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcom_find_freq() or qcom_find_freq_floor(). Only compile tested.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < 5533686e99b04994d7c4877dc0e4282adc9444a25533686e99b04994d7c4877dc0e4282adc9444a2
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < b2dfb216f32627c2f6a8041f2d9d56d102ab87c0b2dfb216f32627c2f6a8041f2d9d56d102ab87c0
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < a09aecb6cb482de88301c43bf00a6c8726c4d34fa09aecb6cb482de88301c43bf00a6c8726c4d34f
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < 3aedcf3755c74dafc187eb76acb04e3e6348b1a93aedcf3755c74dafc187eb76acb04e3e6348b1a9
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < 185de0b7cdeaad8b89ebd4c8a258ff2f21adba99185de0b7cdeaad8b89ebd4c8a258ff2f21adba99
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < 9b4c4546dd61950e80ffdca1bf6925f42b665b039b4c4546dd61950e80ffdca1bf6925f42b665b03
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < 7e5432401536117c316d7f3b21d46b64c1514f387e5432401536117c316d7f3b21d46b64c1514f38
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < 5638330150db2cc30b53eed04e481062faa3ece85638330150db2cc30b53eed04e481062faa3ece8
linuxlinux>= 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd < a903cfd38d8dee7e754fb89fd1bebed99e28003da903cfd38d8dee7e754fb89fd1bebed99e28003d
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 0 < 4.4.0-269.3034.4.0-269.303
linuxlinux_kernel>= 0 < 4.15.0-238.2504.15.0-238.250
linuxlinux_kernel>= 3.17 < 4.19.3124.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.