cbcvebase.
CVE-2024-40994
published 2024-07-12

CVE-2024-40994: In the Linux kernel, the following vulnerability has been resolved: ptp: fix integer overflow in max_vclocks_store On 32bit systems, the "4 * max" multiply can…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ptp: fix integer overflow in max_vclocks_store On 32bit systems, the "4 * max" multiply can overflow. Use kcalloc() to do the allocation to prevent this.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 44c494c8e30e35713c7d11ca3c5ab332cbfabacf < 4b03da87d0b7074c93d9662c6e1a8939f9b8b86e4b03da87d0b7074c93d9662c6e1a8939f9b8b86e
linuxlinux>= 44c494c8e30e35713c7d11ca3c5ab332cbfabacf < d50d62d5e6ee6aa03c00bddb91745d0b632d3b0fd50d62d5e6ee6aa03c00bddb91745d0b632d3b0f
linuxlinux>= 44c494c8e30e35713c7d11ca3c5ab332cbfabacf < 666e934d749e50a37f3796caaf843a605f115b6f666e934d749e50a37f3796caaf843a605f115b6f
linuxlinux>= 44c494c8e30e35713c7d11ca3c5ab332cbfabacf < e1fccfb4638ee6188377867f6015d0ce35764a8ee1fccfb4638ee6188377867f6015d0ce35764a8e
linuxlinux>= 44c494c8e30e35713c7d11ca3c5ab332cbfabacf < 81d23d2a24012e448f651e007fac2cfd20a45ce081d23d2a24012e448f651e007fac2cfd20a45ce0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.14 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.