cbcvebase.
CVE-2024-42301
published 2024-08-17

CVE-2024-42301: In the Linux kernel, the following vulnerability has been resolved: dev/parport: fix the array out-of-bounds risk Fixed array out-of-bounds issues caused by…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: dev/parport: fix the array out-of-bounds risk Fixed array out-of-bounds issues caused by sprintf by replacing it with snprintf for safer data copying, ensuring the destination buffer is not overflowed. Below is the stack trace I encountered during the actual issue: [ 66.575408s] [pid:5118,cpu4,QThread,4]Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: do_hardware_base_addr+0xcc/0xd0 [parport] [ 66.575408s] [pid:5118,cpu4,QThread,5]CPU: 4 PID: 5118 Comm: QThread Tainted: G S W O 5.10.97-arm64-desktop #7100.57021.2 [ 66.575439s] [pid:5118,cpu4,QThread,6]TGID: 5087 Comm: EFileApp [ 66.575439s] [pid:5118,cpu4,QThread,7]Hardware name: HUAWEI HUAWEI QingYun PGUX-W515x-B081/SP1PANGUXM, BIOS 1.00.07 04/29/2024 [ 66.575439s] [pid:5118,cpu4,QThread,8]Call trace: [ 66.575469s] [pid:5118,cpu4,QThread,9] dump_backtrace+0x0/0x1c0 [ 66.575469s] [pid:5118,cpu4,QThread,0] show_stack+0x14/0x20 [ 66.575469s] [pid:5118,cpu4,QThread,1] dump_stack+0xd4/0x10c [ 66.575500s] [pid:5118,cpu4,QThread,2] panic+0x1d8/0x3bc [ 66.575500s] [pid:5118,cpu4,QThread,3] __stack_chk_fail+0x2c/0x38 [ 66.575500s] [pid:5118,cpu4,QThread,4] do_hardware_base_addr+0xcc/0xd0 [parport]

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 166a0bddcc27de41fe13f861c8348e8e53e988c8166a0bddcc27de41fe13f861c8348e8e53e988c8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 47b3dce100778001cd76f7e9188944b5cb27a76d47b3dce100778001cd76f7e9188944b5cb27a76d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a44f88f7576bc1916d8d6293f5c62fbe7cbe03e0a44f88f7576bc1916d8d6293f5c62fbe7cbe03e0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c719b393374d3763e64900ee19aaed767d5a08d6c719b393374d3763e64900ee19aaed767d5a08d6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7f4da759092a1a6ce35fb085182d02de8cc4cc847f4da759092a1a6ce35fb085182d02de8cc4cc84
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b579ea3516c371ecf59d073772bc45dfd28c8a0eb579ea3516c371ecf59d073772bc45dfd28c8a0e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7789a1d6792af410aa9b39a1eb237ed24fa2170a7789a1d6792af410aa9b39a1eb237ed24fa2170a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ab11dac93d2d568d151b1918d7b84c2d02bacbd5ab11dac93d2d568d151b1918d7b84c2d02bacbd5
linuxlinux_kernel< 4.19.3204.19.320
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-269.3034.4.0-269.303
linuxlinux_kernel>= 0 < 4.15.0-238.2504.15.0-238.250
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.