cbcvebase.
CVE-2024-43839
published 2024-08-17

CVE-2024-43839: In the Linux kernel, the following vulnerability has been resolved: bna: adjust 'name' buf size of bna_tcb and bna_ccb structures To have enough space to write…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved:

bna: adjust 'name' buf size of bna_tcb and bna_ccb structures

To have enough space to write all possible sprintf() args. Currently
'name' size is 16, but the first '%s' specifier may already need at
least 16 characters, since 'bnad->netdev->name' is used there.

For '%d' specifiers, assume that they require:
* 1 char for 'tx_id + tx_info->tcb[i]->id' sum, BNAD_MAX_TXQ_PER_TX is 8
* 2 chars for 'rx_id + rx_info->rx_ctrl[i].ccb->id', BNAD_MAX_RXP_PER_RX
is 16

And replace sprintf with snprintf.

Detected using the static analysis tool - Svace.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < f121740f69eda4da2de9a20a6687a13593e72540f121740f69eda4da2de9a20a6687a13593e72540
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < c90b1cd7758fd4839909e838ae195d19f8065d76c90b1cd7758fd4839909e838ae195d19f8065d76
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < 6ce46045f9b90d952602e2c0b8886cfadf860bf16ce46045f9b90d952602e2c0b8886cfadf860bf1
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < 6d20c4044ab4d0e6a99aa35853e66f0aed5589e36d20c4044ab4d0e6a99aa35853e66f0aed5589e3
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < ab748dd10d8742561f2980fea08ffb4f0cacfdefab748dd10d8742561f2980fea08ffb4f0cacfdef
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < b0ff0cd0847b03c0a0abe20cfa900eabcfcb9e43b0ff0cd0847b03c0a0abe20cfa900eabcfcb9e43
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < e0f48f51d55fb187400e9787192eda09fa200ff5e0f48f51d55fb187400e9787192eda09fa200ff5
linuxlinux>= 8b230ed8ec96c933047dd0625cf95f739e4939a6 < c9741a03dc8e491e57b95fba0058ab46b7e506dac9741a03dc8e491e57b95fba0058ab46b7e506da
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 2.6.37 < 4.19.3204.19.320
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.446.6.44

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.