cbcvebase.
CVE-2024-36016
published 2024-05-29

CVE-2024-36016: In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() Assuming the following: - side A…

PriorityP338high7.7CVSS 3.1
AVLACLPRNUINSUCHINAH
EPSS
0.28%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() Assuming the following: - side A configures the n_gsm in basic option mode - side B sends the header of a basic option mode frame with data length 1 - side A switches to advanced option mode - side B sends 2 data bytes which exceeds gsm->len Reason: gsm->len is not used in advanced option mode. - side A switches to basic option mode - side B keeps sending until gsm0_receive() writes past gsm->buf Reason: Neither gsm->state nor gsm->len have been reset after reconfiguration. Fix this by changing gsm->count to gsm->len comparison from equal to less than. Also add upper limit checks against the constant MAX_MRU in gsm0_receive() and gsm1_receive() to harden against memory corruption of gsm->len and gsm->mru. All other checks remain as we still need to limit the data according to the user configuration and actual payload size.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 9513d4148950b05bc99fa7314dc883cc0e1605e59513d4148950b05bc99fa7314dc883cc0e1605e5
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < b229bc6c6ea9fe459fc3fa94fd0a27a2f32aca56b229bc6c6ea9fe459fc3fa94fd0a27a2f32aca56
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 0fb736c9931e02dbc7d9a75044c8e1c039e50f040fb736c9931e02dbc7d9a75044c8e1c039e50f04
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 4c267110fc110390704cc065edb9817fdd10ff544c267110fc110390704cc065edb9817fdd10ff54
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 46f52c89a7e7d2691b97a9728e4591d071ca8abc46f52c89a7e7d2691b97a9728e4591d071ca8abc
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 774d83b008eccb1c48c14dc5486e7aa255731350774d83b008eccb1c48c14dc5486e7aa255731350
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < f126ce7305fe88f49cdabc6db4168b9318898ea3f126ce7305fe88f49cdabc6db4168b9318898ea3
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < b890d45aaf02b564e6cae2d2a590f9649330857db890d45aaf02b564e6cae2d2a590f9649330857d
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 47388e807f85948eefc403a8a5fdc5b406a65d5a47388e807f85948eefc403a8a5fdc5b406a65d5a
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-190.2105.4.0-190.210
linuxlinux_kernel>= 0 < 5.15.0-117.1275.15.0-117.127
linuxlinux_kernel>= 0 < 6.8.0-39.396.8.0-39.39
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 0 < 4.15.0-227.2394.15.0-227.239
linuxlinux_kernel>= 0 < 5.4.0-190.2105.4.0-190.210
linuxlinux_kernel>= 0 < 5.15.0-117.1275.15.0-117.127
linuxlinux_kernel>= 0 < 6.8.0-39.396.8.0-39.39
linuxlinux_kernel>= 2.6.35 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.