CVE-2024-27436 — Out-of-bounds Write in Linux
Severity
5.5MEDIUMNVD
OSV7.8OSV7.0OSV6.5
EPSS
0.1%
top 64.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateNov 14
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Stop parsing channels bits when all channels are found.
If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages9 packages
▶CVEListV5linux/linux04324ccc75f96b3ed7aad1c866d1b7925e977bdf — 7e2c1b0f6dd9abde9e60f0f9730026714468770f+9
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
25OSV▶
linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities↗2024-10-15
📋Vendor Advisories
26💬Community
1Bugzilla▶
CVE-2024-27436 kernel: ALSA: usb-audio: Stop parsing channels bits when all channels are found.↗2024-05-17