cbcvebase.
CVE-2024-36934
published 2024-05-30

CVE-2024-36934: In the Linux kernel, the following vulnerability has been resolved: bna: ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.9th percentile
In the Linux kernel, the following vulnerability has been resolved: bna: ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel buffer and copy nbytes from userspace to that buffer. Later, we use sscanf on this buffer but we don't ensure that the string is terminated inside the buffer, this can lead to OOB read when using sscanf. Fix this issue by using memdup_user_nul instead of memdup_user.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < bd502ba81cd1d515deddad7dbc6b812b14b97147bd502ba81cd1d515deddad7dbc6b812b14b97147
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < 80578ec10335bc15ac35fd1703c22aab34e39fdd80578ec10335bc15ac35fd1703c22aab34e39fdd
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < 6f0f19b79c085cc891c418b768f26f7004bd51a46f0f19b79c085cc891c418b768f26f7004bd51a4
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < 0f560240b4cc25d3de527deb257cdf072c0102a90f560240b4cc25d3de527deb257cdf072c0102a9
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < 06cb37e2ba6441888f24566a997481d4197b4e3206cb37e2ba6441888f24566a997481d4197b4e32
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < e19478763154674c084defc62ae0d64d79657f91e19478763154674c084defc62ae0d64d79657f91
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < 1518b2b498a0109eb6b15755169d3b6607356b351518b2b498a0109eb6b15755169d3b6607356b35
linuxlinux>= 7afc5dbde09104b023ce04465ba71aaba0fc4346 < 8c34096c7fdf272fd4c0c37fe411cd2e3ed0ee9f8c34096c7fdf272fd4c0c37fe411cd2e3ed0ee9f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 3.3 < 4.19.3144.19.314
linuxlinux_kernel>= 4.20 < 5.4.2765.4.276
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.