cbcvebase.
CVE-2024-42238
published 2024-08-07

CVE-2024-42238: In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.5th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if a block header is longer than the amount of data left in the file. The previous code in cs_dsp_load() and cs_dsp_load_coeff() would loop while there was enough data left in the file for a valid region. This protected against overrunning the end of the file data, but it didn't abort the file processing with an error.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= f6bc909e7673c30abcbdb329e7d0aa2e83c103d7 < b8be70566b33abbd0180105070b4c67cfef8c44fb8be70566b33abbd0180105070b4c67cfef8c44f
linuxlinux>= f6bc909e7673c30abcbdb329e7d0aa2e83c103d7 < 90ab191b7d181057d71234e8632e06b5844ac38e90ab191b7d181057d71234e8632e06b5844ac38e
linuxlinux>= f6bc909e7673c30abcbdb329e7d0aa2e83c103d7 < 6eabd23383805725eff416c203688b7a390d41536eabd23383805725eff416c203688b7a390d4153
linuxlinux>= f6bc909e7673c30abcbdb329e7d0aa2e83c103d7 < 959fe01e85b7241e3ec305d657febbe82da16a02959fe01e85b7241e3ec305d657febbe82da16a02
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.16 < 6.1.1006.1.100
linuxlinux_kernel>= 6.2 < 6.6.416.6.41
linuxlinux_kernel>= 6.7 < 6.9.106.9.10
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.