cbcvebase.
CVE-2024-36898
published 2024-05-30

CVE-2024-36898: In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line is requested with debounce, and that…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line is requested with debounce, and that results in debouncing in software, and the line is subsequently reconfigured to enable edge detection then the allocation of the kfifo to contain edge events is overlooked. This results in events being written to and read from an uninitialised kfifo. Read events are returned to userspace. Initialise the kfifo in the case where the software debounce is already active.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 65cff70464068a823b3f4a28074000febdce0630 < c87cc32bc48b187067e089b15ab7a6a7eed5767dc87cc32bc48b187067e089b15ab7a6a7eed5767d
linuxlinux>= 65cff70464068a823b3f4a28074000febdce0630 < 1a51e24404d77bb3307c1e39eee0d8e86febb1a51a51e24404d77bb3307c1e39eee0d8e86febb1a5
linuxlinux>= 65cff70464068a823b3f4a28074000febdce0630 < 883e4bbf06eb5fb7482679e4edb201093e9f55a2883e4bbf06eb5fb7482679e4edb201093e9f55a2
linuxlinux>= 65cff70464068a823b3f4a28074000febdce0630 < bd7139a70ee8d8ea872b223e043730cf6f5e2b0ebd7139a70ee8d8ea872b223e043730cf6f5e2b0e
linuxlinux>= 65cff70464068a823b3f4a28074000febdce0630 < ee0166b637a5e376118e9659e5b4148080f1d27eee0166b637a5e376118e9659e5b4148080f1d27e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.10 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure-5.15
ubuntulinux-azure-fde

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.