cbcvebase.
CVE-2024-38560
published 2024-06-19

CVE-2024-38560: In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.27%
18.3th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel buffer and copy nbytes from userspace to that buffer. Later, we use sscanf on this buffer but we don't ensure that the string is terminated inside the buffer, this can lead to OOB read when using sscanf. Fix this issue by using memdup_user_nul instead of memdup_user.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 481fc0c8617304a67649027c4a44723a139a0462481fc0c8617304a67649027c4a44723a139a0462
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 595a6b98deec01b6dbb20139f71edcd5fb760ec2595a6b98deec01b6dbb20139f71edcd5fb760ec2
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 00b425ff0891283207d7bad607a2412225274d7a00b425ff0891283207d7bad607a2412225274d7a
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 1708e3cf2488788cba5489e4f913d227de757baf1708e3cf2488788cba5489e4f913d227de757baf
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 7d3e694c4fe30f3aba9cd5ae86fb947a54c3db5c7d3e694c4fe30f3aba9cd5ae86fb947a54c3db5c
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 204714e68015d6946279719fd464ecaf57240f35204714e68015d6946279719fd464ecaf57240f35
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 7510fab46b1cbd1680e2a096e779aec3334b41437510fab46b1cbd1680e2a096e779aec3334b4143
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < ecb76200f5557a2886888aaa53702da1ab9e6cdfecb76200f5557a2886888aaa53702da1ab9e6cdf
linuxlinux>= 9f30b674759b9a2da25aefe25d885161d8a911cb < 13d0cecb4626fae67c00c84d3c7851f6b62f7df313d0cecb4626fae67c00c84d3c7851f6b62f7df3
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 3.19 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2195.10.219

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.