cbcvebase.
CVE-2024-36974
published 2024-06-18

CVE-2024-36974: In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate it, or userspace can inject arbitrary data to the kernel, the second time taprio_change() is called. First call (with valid attributes) sets dev->num_tc to a non zero value. Second call (with arbitrary mqprio attributes) returns early from taprio_parse_mqprio_opt() and bad things can happen.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < c6041e7124464ce7e896ee3f912897ce88a0c4ecc6041e7124464ce7e896ee3f912897ce88a0c4ec
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < 6db4af09987cc5d5f0136bd46148b0e0460dae5b6db4af09987cc5d5f0136bd46148b0e0460dae5b
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < d3dde4c217f0c31ab0621912e682b57e677dd923d3dde4c217f0c31ab0621912e682b57e677dd923
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < 0bf6cc96612bd396048f57d63f1ad454a846e39c0bf6cc96612bd396048f57d63f1ad454a846e39c
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < 724050ae4b76e4fae05a923cb54101d792cf4404724050ae4b76e4fae05a923cb54101d792cf4404
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < c37a27a35eadb59286c9092c49c241270c802ae2c37a27a35eadb59286c9092c49c241270c802ae2
linuxlinux>= a3d43c0d56f1b94e74963a2fbadfb70126d92213 < f921a58ae20852d188f70842431ce6519c4fdc36f921a58ae20852d188f70842431ce6519c4fdc36
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 5.2 < 5.4.2795.4.279
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.