cbcvebase.
CVE-2024-36931
published 2024-05-30

CVE-2024-36931: In the Linux kernel, the following vulnerability has been resolved: s390/cio: Ensure the copied buf is NUL terminated Currently, we allocate a lbuf-sized…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/cio: Ensure the copied buf is NUL terminated Currently, we allocate a lbuf-sized kernel buffer and copy lbuf from userspace to that buffer. Later, we use scanf on this buffer but we don't ensure that the string is terminated inside the buffer, this can lead to OOB read when using scanf. Fix this issue by using memdup_user_nul instead.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= a4f17cc726712a52122ad38540bc3ff3a052d1a4 < c9d48ce163305595ae20aee27774192476d5e6a5c9d48ce163305595ae20aee27774192476d5e6a5
linuxlinux>= a4f17cc726712a52122ad38540bc3ff3a052d1a4 < 10452edd175fcc4fd0f5ac782ed2a002e3e5d65c10452edd175fcc4fd0f5ac782ed2a002e3e5d65c
linuxlinux>= a4f17cc726712a52122ad38540bc3ff3a052d1a4 < 84b38f48836662c4bfae646c014f4e981e16a2b284b38f48836662c4bfae646c014f4e981e16a2b2
linuxlinux>= a4f17cc726712a52122ad38540bc3ff3a052d1a4 < 06759ebaf75c19c87b2453a5e130e9e61e9b5d6506759ebaf75c19c87b2453a5e130e9e61e9b5d65
linuxlinux>= a4f17cc726712a52122ad38540bc3ff3a052d1a4 < da7c622cddd4fe36be69ca61e8c42e43cde94784da7c622cddd4fe36be69ca61e8c42e43cde94784
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.13 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.