cbcvebase.
CVE-2024-27413
published 2024-05-17

CVE-2024-27413: In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect allocation size gcc-14 notices that the allocation with…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect allocation size gcc-14 notices that the allocation with sizeof(void) on 32-bit architectures is not enough for a 64-bit phys_addr_t: drivers/firmware/efi/capsule-loader.c: In function 'efi_capsule_open': drivers/firmware/efi/capsule-loader.c:295:24: error: allocation of insufficient size '4' for type 'phys_addr_t' {aka 'long long unsigned int'} with size '8' [-Werror=alloc-size] 295 | cap_info->phys = kzalloc(sizeof(void *), GFP_KERNEL); | ^ Use the correct type instead here.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4.14.13 < 4.154.15
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < 00cf21ac526011a29fc708f8912da446fac19f7b00cf21ac526011a29fc708f8912da446fac19f7b
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < 950d4d74d311a18baed6878dbfba8180d7e5dddd950d4d74d311a18baed6878dbfba8180d7e5dddd
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < 537e3f49dbe88881a6f0752beaa596942d9efd64537e3f49dbe88881a6f0752beaa596942d9efd64
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < 4b73473c050a612fb4317831371073eda07c30504b73473c050a612fb4317831371073eda07c3050
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < ddc547dd05a46720866c32022300f7376c40119fddc547dd05a46720866c32022300f7376c40119f
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < 11aabd7487857b8e7d768fefb092f66dfde6849211aabd7487857b8e7d768fefb092f66dfde68492
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < 62a5dcd9bd3097e9813de62fa6f22815e84a017262a5dcd9bd3097e9813de62fa6f22815e84a0172
linuxlinux>= f24c4d478013d82bd1b943df566fff3561d52864 < fccfa646ef3628097d59f7d9c1a3e84d4b6bb45efccfa646ef3628097d59f7d9c1a3e84d4b6bb45e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.14.13 < 4.154.15
linuxlinux_kernel>= 4.15.1 < 4.19.3094.19.309
linuxlinux_kernel>= 4.20 < 5.4.2715.4.271
linuxlinux_kernel>= 5.11 < 5.15.1515.15.151

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.