cbcvebase.
CVE-2024-26970
published 2024-05-01

CVE-2024-26970: In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-ipq6018: fix terminating of frequency table arrays The frequency table…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-ipq6018: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcom_find_freq() or qcom_find_freq_floor(). Only compile tested.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < ae60e3342296f766f88911d39199f77b05f657a6ae60e3342296f766f88911d39199f77b05f657a6
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < b4527ee3de365a742215773d20f07db3e2c06f3bb4527ee3de365a742215773d20f07db3e2c06f3b
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < 852db52b45ea96dac2720f108e7c7331cd3738bb852db52b45ea96dac2720f108e7c7331cd3738bb
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < 421b135aceace99789c982f6a77ce9476564fb52421b135aceace99789c982f6a77ce9476564fb52
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < dcb13b5c9ae8743f99a96f392186527c3df89198dcb13b5c9ae8743f99a96f392186527c3df89198
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < db4066e3ab6b3d918ae2b92734a89c04fe82cc1ddb4066e3ab6b3d918ae2b92734a89c04fe82cc1d
linuxlinux>= d9db07f088af01a1080d01de363141b673c7d646 < cdbc6e2d8108bc47895e5a901cfcaf799b00ca8dcdbc6e2d8108bc47895e5a901cfcaf799b00ca8d
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 5.6 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.