cbcvebase.
CVE-2024-38576
published 2024-06-19

CVE-2024-38576: In the Linux kernel, the following vulnerability has been resolved: rcu: Fix buffer overflow in print_cpu_stall_info() The rcuc-starvation output from…

PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.7th percentile
In the Linux kernel, the following vulnerability has been resolved: rcu: Fix buffer overflow in print_cpu_stall_info() The rcuc-starvation output from print_cpu_stall_info() might overflow the buffer if there is a huge difference in jiffies difference. The situation might seem improbable, but computers sometimes get very confused about time, which can result in full-sized integers, and, in this case, buffer overflow. Also, the unsigned jiffies difference is printed using %ld, which is normally for signed integers. This is intentional for debugging purposes, but it is not obvious from the code. This commit therefore changes sprintf() to snprintf() and adds a clarifying comment about intention of %ld format. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 245a62982502255314b63dd2c4daaedd1cd595a6 < e2228ed3fe7aa838fba87c79a76fb1ad9ea47138e2228ed3fe7aa838fba87c79a76fb1ad9ea47138
linuxlinux>= 245a62982502255314b63dd2c4daaedd1cd595a6 < afb39909bfb5c08111f99e21bf5be7505f59ff1cafb39909bfb5c08111f99e21bf5be7505f59ff1c
linuxlinux>= 245a62982502255314b63dd2c4daaedd1cd595a6 < 9351e1338539cb7f319ffc1210fa9b2aa27384b59351e1338539cb7f319ffc1210fa9b2aa27384b5
linuxlinux>= 245a62982502255314b63dd2c4daaedd1cd595a6 < 4c3e2ef4d8ddd313c8ce3ac30505940bea8d62574c3e2ef4d8ddd313c8ce3ac30505940bea8d6257
linuxlinux>= 245a62982502255314b63dd2c4daaedd1cd595a6 < 3758f7d9917bd7ef0482c4184c0ad673b4c4e0693758f7d9917bd7ef0482c4184c0ad673b4c4e069
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.0 < 6.1.936.1.93
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.