CVE-2024-36960 — Out-of-bounds Read in Linux
Severity
7.1HIGHNVD
OSV7.8OSV6.5OSV5.5
EPSS
0.0%
top 98.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix invalid reads in fence signaled events
Correctly set the length of the drm_event to the size of the structure
that's actually used.
The length of the drm_event was set to the parent structure instead of
to the drm_vmw_event_fence which is supposed to be read. drm_read
uses the length parameter to copy the event to the user space thus
resuling in oob reads.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages5 packages
▶CVEListV5linux/linux8b7de6aa84682a3396544fd88cd457f95484573a — 2f527e3efd37c7c5e85e8aa86308856b619fa59f+8
Also affects: Debian Linux 10.0