cbcvebase.
CVE-2024-38579
published 2024-06-19

CVE-2024-38579: In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - Fix pointer arithmetic In spu2_dump_omd() value of ptr is increased by…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.9th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - Fix pointer arithmetic In spu2_dump_omd() value of ptr is increased by ciph_key_len instead of hash_iv_len which could lead to going beyond the buffer boundaries. Fix this bug by changing ciph_key_len to hash_iv_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < c256b616067bfd6d274c679c06986b78d2402434c256b616067bfd6d274c679c06986b78d2402434
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < e719c8991c161977a67197775067ab456b518c7be719c8991c161977a67197775067ab456b518c7b
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < ebed0d666fa709bae9e8cafa8ec6e7ebd1d318c6ebed0d666fa709bae9e8cafa8ec6e7ebd1d318c6
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < c69a1e4b419c2c466dd8c5602bdebadc353973ddc69a1e4b419c2c466dd8c5602bdebadc353973dd
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 49833a8da6407e7e9b532cc4054fdbcaf78f5fdd49833a8da6407e7e9b532cc4054fdbcaf78f5fdd
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < d0f14ae223c2421b334c1f1a9e48f1e809aee3a0d0f14ae223c2421b334c1f1a9e48f1e809aee3a0
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < c0082ee420639a97e40cae66778b02b341b005e5c0082ee420639a97e40cae66778b02b341b005e5
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 3b7a40740f04e2f27114dfd6225c5e721dda9d573b7a40740f04e2f27114dfd6225c5e721dda9d57
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 2b3460cbf454c6b03d7429e9ffc4fe09322eb1a92b3460cbf454c6b03d7429e9ffc4fe09322eb1a9
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 4.11 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2195.10.219
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.