cbcvebase.
CVE-2024-40963
published 2024-07-12

CVE-2024-40963: In the Linux kernel, the following vulnerability has been resolved: mips: bmips: BCM6358: make sure CBR is correctly set It was discovered that some device…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved: mips: bmips: BCM6358: make sure CBR is correctly set It was discovered that some device have CBR address set to 0 causing kernel panic when arch_sync_dma_for_cpu_all is called. This was notice in situation where the system is booted from TP1 and BMIPS_GET_CBR() returns 0 instead of a valid address and !!(read_c0_brcm_cmt_local() & (1 << 31)); not failing. The current check whether RAC flush should be disabled or not are not enough hence lets check if CBR is a valid address or not.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2cdbcff99f15db86a10672fb220379a1ae46ccae < 6c0f6ccd939166f56a904c792d7fcadae43b90856c0f6ccd939166f56a904c792d7fcadae43b9085
linuxlinux>= 47a449ec09b4479b89dcc6b27ec3829fc82ffafb < 36d771ce6028b886e18a4a8956a5d23688e4e13d36d771ce6028b886e18a4a8956a5d23688e4e13d
linuxlinux>= 5.10.177 < 5.10.2215.10.221
linuxlinux>= 5.15.106 < 5.15.1625.15.162
linuxlinux>= 5.4.240 < 5.4.2795.4.279
linuxlinux>= 6.1.23 < 6.1.966.1.96
linuxlinux>= 6.2.10 < 6.36.3
linuxlinux>= 65b723644294f1d79770704162c0e8d1f700b6f1 < 89167072fd249e5f23ae2f8093f87da5925cef2789167072fd249e5f23ae2f8093f87da5925cef27
linuxlinux>= ab327f8acdf8d06601fbf058859a539a9422afff < 2cd4854ef14a487bcfb76c7980675980cad27b522cd4854ef14a487bcfb76c7980675980cad27b52
linuxlinux>= ab327f8acdf8d06601fbf058859a539a9422afff < da895fd6da438af8d9326b8f02d715a9c76c3b5bda895fd6da438af8d9326b8f02d715a9c76c3b5b
linuxlinux>= ab327f8acdf8d06601fbf058859a539a9422afff < ce5cdd3b05216b704a704f466fb4c2dff3778cafce5cdd3b05216b704a704f466fb4c2dff3778caf
linuxlinux>= d65de5ee8b72868fbbbd39ca73017d0e526fa13a < 10afe5f7d30f6fe50c2b1177549d0e04921fc37310afe5f7d30f6fe50c2b1177549d0e04921fc373
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.