cbcvebase.
CVE-2024-36978
published 2024-06-19

CVE-2024-36978: In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be used in kmalloc. Otherwise, an out-of-bounds write will occur.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
googleandroid
linuxlinux
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < d5d9d241786f49ae7cbc08e7fc95a115e9d80f3dd5d9d241786f49ae7cbc08e7fc95a115e9d80f3d
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < 52b1aa07cda6a199cd6754d3798c7759023bc70f52b1aa07cda6a199cd6754d3798c7759023bc70f
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < 598572c64287aee0b75bbba4e2881496878860f3598572c64287aee0b75bbba4e2881496878860f3
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < 0f208fad86631e005754606c3ec80c0d44a118820f208fad86631e005754606c3ec80c0d44a11882
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < 54c2c171c11a798fe887b3ff72922aa9d1411c1e54c2c171c11a798fe887b3ff72922aa9d1411c1e
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < d6fb5110e8722bc00748f22caeb650fe4672f129d6fb5110e8722bc00748f22caeb650fe4672f129
linuxlinux>= c2999f7fb05b87da4060e38150c70fa46794d82b < affc18fdc694190ca7575b9a86632a73b9fe043daffc18fdc694190ca7575b9a86632a73b9fe043d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 5.4 < 5.4.2795.4.279
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.