cbcvebase.
CVE-2024-36477
published 2024-06-21

CVE-2024-36477: In the Linux kernel, the following vulnerability has been resolved: tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer The TPM SPI…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer The TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the maximum transfer length and the size of the transfer buffer. As such, it does not account for the 4 bytes of header that prepends the SPI data frame. This can result in out-of-bounds accesses and was confirmed with KASAN. Introduce SPI_HDRSIZE to account for the header and use to allocate the transfer buffer.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.7-1 (forky)linux 6.9.7-1 (forky)
linuxlinux
linuxlinux>= a86a42ac2bd652fdc7836a9d880c306a2485c142 < 1547183852dcdfcc25878db7dd3620509217b0cd1547183852dcdfcc25878db7dd3620509217b0cd
linuxlinux>= a86a42ac2bd652fdc7836a9d880c306a2485c142 < de13c56f99477b56980c7e00b09c776d16b7563dde13c56f99477b56980c7e00b09c776d16b7563d
linuxlinux>= a86a42ac2bd652fdc7836a9d880c306a2485c142 < 195aba96b854dd664768f382cd1db375d8181f88195aba96b854dd664768f382cd1db375d8181f88
linuxlinux_kernel< 6.6.336.6.33
linuxlinux_kernel< 6.9.46.9.4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
msrcazl3_kernel_6.6.29.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-4_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.160.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.