cbcvebase.
CVE-2024-38585
published 2024-06-19

CVE-2024-38585: In the Linux kernel, the following vulnerability has been resolved: tools/nolibc/stdlib: fix memory error in realloc() Pass user_p_len to memcpy() instead of…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tools/nolibc/stdlib: fix memory error in realloc() Pass user_p_len to memcpy() instead of heap->len to prevent realloc() from copying an extra sizeof(heap) bytes from beyond the allocated region.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 0e0ff638400be8f497a35b51a4751fd823f6bd6a < 5996b2b2dac739f2a27da13de8eee5b85b2550b35996b2b2dac739f2a27da13de8eee5b85b2550b3
linuxlinux>= 0e0ff638400be8f497a35b51a4751fd823f6bd6a < f678c3c336559cf3255a32153e9a17c1be4e7c15f678c3c336559cf3255a32153e9a17c1be4e7c15
linuxlinux>= 0e0ff638400be8f497a35b51a4751fd823f6bd6a < 8019d3dd921f39a237a9fab6d2ce716bfac0f9838019d3dd921f39a237a9fab6d2ce716bfac0f983
linuxlinux>= 0e0ff638400be8f497a35b51a4751fd823f6bd6a < 4e6f225aefeb712cdb870176b6621f02cf235b8c4e6f225aefeb712cdb870176b6621f02cf235b8c
linuxlinux>= 0e0ff638400be8f497a35b51a4751fd823f6bd6a < 791f4641142e2aced85de082e5783b4fb0b977c2791f4641142e2aced85de082e5783b4fb0b977c2
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.19 < 6.1.936.1.93
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.