cbcvebase.
CVE-2024-35823
published 2024-05-17

CVE-2024-35823: In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.91%
56.4th percentile
In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting chars in the buffer"). The cure is also the same i.e. replace memcpy() with memmove() due to the overlaping buffers.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < fc7dfe3d123f00e720be80b920da287810a1f37dfc7dfe3d123f00e720be80b920da287810a1f37d
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < ff7342090c1e8c5a37015c89822a68b275b46f8aff7342090c1e8c5a37015c89822a68b275b46f8a
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 1ce408f75ccf1e25b3fddef75cca878b55f2ac901ce408f75ccf1e25b3fddef75cca878b55f2ac90
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 0190d19d7651c08abc187dac3819c61b726e7e3f0190d19d7651c08abc187dac3819c61b726e7e3f
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 994a1e583c0c206c8ca7d03334a65b79f4d8bc51994a1e583c0c206c8ca7d03334a65b79f4d8bc51
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 7529cbd8b5f6697b369803fe1533612c039cabda7529cbd8b5f6697b369803fe1533612c039cabda
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 2933b1e4757a0a5c689cf48d80b1a2a85f237ff12933b1e4757a0a5c689cf48d80b1a2a85f237ff1
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 1581dafaf0d34bc9c428a794a22110d7046d186d1581dafaf0d34bc9c428a794a22110d7046d186d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 3.7 < 4.19.3124.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.