cbcvebase.
CVE-2024-36960
published 2024-06-03

CVE-2024-36960: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.29%
20.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was set to the parent structure instead of to the drm_vmw_event_fence which is supposed to be read. drm_read uses the length parameter to copy the event to the user space thus resuling in oob reads.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < 2f527e3efd37c7c5e85e8aa86308856b619fa59f2f527e3efd37c7c5e85e8aa86308856b619fa59f
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < cef0962f2d3e5fd0660c8efb72321083a1b531a9cef0962f2d3e5fd0660c8efb72321083a1b531a9
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < 3cd682357c6167f636aec8ac0efaa8ba61144d363cd682357c6167f636aec8ac0efaa8ba61144d36
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < b7bab33c4623c66e3398d5253870d4e88c52dfc0b7bab33c4623c66e3398d5253870d4e88c52dfc0
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < 0dbfc73670b357456196130551e586345ca48e1b0dbfc73670b357456196130551e586345ca48e1b
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < 7b5fd3af4a250dd0a2a558e07b43478748eb5d227b5fd3af4a250dd0a2a558e07b43478748eb5d22
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < deab66596dfad14f1c54eeefdb72428340d72a77deab66596dfad14f1c54eeefdb72428340d72a77
linuxlinux>= 8b7de6aa84682a3396544fd88cd457f95484573a < a37ef7613c00f2d72c8fc08bd83fb6cc76926c8ca37ef7613c00f2d72c8fc08bd83fb6cc76926c8c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 3.4 < 4.19.3144.19.314
linuxlinux_kernel>= 4.20 < 5.4.2765.4.276
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 5.5 < 5.10.2175.10.217
linuxlinux_kernel>= 6.2 < 6.6.316.6.31

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.