cbcvebase.
CVE-2024-42284
published 2024-08-17

CVE-2024-42284: In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should return non-zero value if the UDP media address is invalid. Otherwise, a buffer overflow access can occur in tipc_media_addr_printf(). Fix this by returning 1 on an invalid UDP media address.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < 7ec3335dd89c8d169e9650e4bac64fde71fdf15b7ec3335dd89c8d169e9650e4bac64fde71fdf15b
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < 253405541be2f15ffebdeac2f4cf4b7e9144d12f253405541be2f15ffebdeac2f4cf4b7e9144d12f
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < aa38bf74899de07cf70b50cd17f8ad45fb6654c8aa38bf74899de07cf70b50cd17f8ad45fb6654c8
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < 5eea127675450583680c8170358bcba43227bd695eea127675450583680c8170358bcba43227bd69
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < 728734352743a78b4c5a7285b282127696a4a813728734352743a78b4c5a7285b282127696a4a813
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < 76ddf84a52f0d8ec3f5db6ccce08faf202a17d2876ddf84a52f0d8ec3f5db6ccce08faf202a17d28
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < 2abe350db1aa599eeebc6892237d0bce0f1de62a2abe350db1aa599eeebc6892237d0bce0f1de62a
linuxlinux>= d0f91938bede204a343473792529e0db7d599836 < fa96c6baef1b5385e2f0c0677b32b3839e716076fa96c6baef1b5385e2f0c0677b32b3839e716076
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-260.2944.4.0-260.294
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 4.1 < 4.19.3204.19.320
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.