CVE-2024-36916 — Out-of-bounds Read in Linux
Severity
7.1HIGHNVD
OSV6.5OSV5.5
EPSS
0.0%
top 93.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 30
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
blk-iocost: avoid out of bounds shift
UBSAN catches undefined behavior in blk-iocost, where sometimes
iocg->delay is shifted right by a number that is too large,
resulting in undefined behavior on some architectures.
[ 186.556576] ------------[ cut here ]------------
UBSAN: shift-out-of-bounds in block/blk-iocost.c:1366:23
shift exponent 64 is too large for 64-bit type 'u64' (aka 'unsigned long long')
CPU: 16 PID: 0 Comm: swa…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages5 packages
▶CVEListV5linux/linux5160a5a53c0c4ae3708959d9465ea43ad5d90542 — 62accf6c1d7b433752cb3591bba8967b7a801ad5+6
Also affects: Debian Linux 10.0