cbcvebase.
CVE-2024-39499
published 2024-07-12

CVE-2024-39499: In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.30%
22.2th percentile
In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-space, event_msg->event_data.event is passed to event_deliver() and used as an index without sanitization. This change ensures that the event index is sanitized to mitigate any possibility of speculative information leaks. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc. Only compile tested, no access to HW.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < 58730dfbd4ae01c1b022b0d234a8bf8c02cdfb8158730dfbd4ae01c1b022b0d234a8bf8c02cdfb81
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < 681967c4ff210e06380acf9b9a1b33ae06e77cbd681967c4ff210e06380acf9b9a1b33ae06e77cbd
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < f70ff737346744633e7b655c1fb23e1578491ff3f70ff737346744633e7b655c1fb23e1578491ff3
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < 95ac3e773a1f8da83c4710a720fbfe80055aafae95ac3e773a1f8da83c4710a720fbfe80055aafae
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < 95bac1c8bedb362374ea1937b1d3e833e01174ee95bac1c8bedb362374ea1937b1d3e833e01174ee
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < e293c6b38ac9029d76ff0d2a6b2d74131709a9a8e293c6b38ac9029d76ff0d2a6b2d74131709a9a8
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < 757804e1c599af5d2a7f864c8e8b2842406ff4bb757804e1c599af5d2a7f864c8e8b2842406ff4bb
linuxlinux>= 1d990201f9bb499b7c76ab00abeb7e803c0bcb2a < 8003f00d895310d409b2bf9ef907c56b42a4e0f48003f00d895310d409b2bf9ef907c56b42a4e0f4
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 3.9 < 4.19.3174.19.317
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.