cbcvebase.
CVE-2024-27075
published 2024-05-01

CVE-2024-27075: In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: avoid stack overflow warnings with clang A previous patch worked…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.2th percentile
In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: avoid stack overflow warnings with clang A previous patch worked around a KASAN issue in stv0367, now a similar problem showed up with clang: drivers/media/dvb-frontends/stv0367.c:1222:12: error: stack frame size (3624) exceeds limit (2048) in 'stv0367ter_set_frontend' [-Werror,-Wframe-larger-than] 1214 | static int stv0367ter_set_frontend(struct dvb_frontend *fe) Rework the stv0367_writereg() function to be simpler and mark both register access functions as noinline_for_stack so the temporary i2c_msg structures do not get duplicated on the stack when KASAN_STACK is enabled.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < c073c8cede5abd3836e83d70d72606d11d0759d4c073c8cede5abd3836e83d70d72606d11d0759d4
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < fa8b472952ef46eb632825051078c21ce0cafe55fa8b472952ef46eb632825051078c21ce0cafe55
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < fb07104a02e87c06c39914d13ed67fd8f839ca82fb07104a02e87c06c39914d13ed67fd8f839ca82
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < d20b64f156de5d10410963fe238d82a4e7e97a2fd20b64f156de5d10410963fe238d82a4e7e97a2f
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < 107052a8cfeff3a97326277192b4f052e4860a8a107052a8cfeff3a97326277192b4f052e4860a8a
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < 8fad9c5bb00d3a9508d18bbfe832e33a473777308fad9c5bb00d3a9508d18bbfe832e33a47377730
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < d6b4895197ab5a47cb81c6852d49320b05052960d6b4895197ab5a47cb81c6852d49320b05052960
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < ed514ecf4f29c80a2f09ae3c877059b401efe893ed514ecf4f29c80a2f09ae3c877059b401efe893
linuxlinux>= 3cd890dbe2a4f14cc44c85bb6cf37e5e22d4dd0e < 7a4cf27d1f0538f779bf31b8c99eda394e2771197a4cf27d1f0538f779bf31b8c99eda394e277119
linuxlinux>= 4.14.20 < 4.154.15
linuxlinux>= 4.15.4 < 4.164.16
linuxlinux>= 4.4.168 < 4.54.5
linuxlinux>= 4.9.82 < 4.104.10
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8MEDIUM
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.