cbcvebase.
CVE-2024-35813
published 2024-05-17

CVE-2024-35813: In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid negative index with array access Commit 4d0c8d0aef63 ("mmc: core: Use…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid negative index with array access Commit 4d0c8d0aef63 ("mmc: core: Use mrq.sbc in close-ended ffu") assigns prev_idata = idatas[i - 1], but doesn't check that the iterator i is greater than zero. Let's fix this by adding a check.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 1653a8102868264f3488c298a9f20af2add9a288 < 4466677dcabe2d70de6aa3d4bd4a4fafa94a71f24466677dcabe2d70de6aa3d4bd4a4fafa94a71f2
linuxlinux>= 4d0c8d0aef6355660b6775d57ccd5d4ea2e15802 < 7d0e8a6147550aa058fa6ade8583ad252aa613047d0e8a6147550aa058fa6ade8583ad252aa61304
linuxlinux>= 4d0c8d0aef6355660b6775d57ccd5d4ea2e15802 < cf55a7acd1ed38afe43bba1c8a0935b51d1dc014cf55a7acd1ed38afe43bba1c8a0935b51d1dc014
linuxlinux>= 5.10.210 < 5.10.2155.10.215
linuxlinux>= 5.15.149 < 5.15.1545.15.154
linuxlinux>= 5.4.269 < 5.4.2745.4.274
linuxlinux>= 50b8b7a22e90bab9f1949b64a88ff17ab10913ec < 81b8645feca08a54c7c4bf36e7b176f4983b2f2881b8645feca08a54c7c4bf36e7b176f4983b2f28
linuxlinux>= 59020bf0999ff7da8aedcd00ef8f0d75d93b6d20 < 2b539c88940e22494da80a93ee1c5a28bbad10f62b539c88940e22494da80a93ee1c5a28bbad10f6
linuxlinux>= 6.1.76 < 6.1.846.1.84
linuxlinux>= 6.6.15 < 6.6.246.6.24
linuxlinux>= 6.7.3 < 6.7.126.7.12
linuxlinux>= c4edcd134bb72b3b0acc884612d624e48c9d057f < ad9cc5e9e53ab94aa0c7ac65d43be7eb208dcb55ad9cc5e9e53ab94aa0c7ac65d43be7eb208dcb55
linuxlinux>= eed9119f8f8e8fbf225c08abdbb58597fba807e0 < 064db53f9023a2d5877a2d12de6bc27995f6ca56064db53f9023a2d5877a2d12de6bc27995f6ca56
linuxlinux>= f49f9e802785291149bdc9c824414de4604226b4 < b9a7339ae403035ffe7fc37cb034b36947910f68b9a7339ae403035ffe7fc37cb034b36947910f68
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.