cbcvebase.
CVE-2024-43877
published 2024-08-21

CVE-2024-43877: In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In case DMA fails, 'dma->SG_length' is 0…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.22%
12.4th percentile
In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In case DMA fails, 'dma->SG_length' is 0. This value is later used to access 'dma->SGarray[dma->SG_length - 1]', which will cause out of bounds access. Add check to return early on invalid value. Adjust warnings accordingly. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 < 24062aa7407091dee3e45a8e8037df437e84871824062aa7407091dee3e45a8e8037df437e848718
linuxlinux>= 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 < 3d8fd92939e21ff0d45100ab208f8124af79402a3d8fd92939e21ff0d45100ab208f8124af79402a
linuxlinux>= 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 < c766065e8272085ea9c436414b7ddf1f12e7787bc766065e8272085ea9c436414b7ddf1f12e7787b
linuxlinux>= 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 < 629913d6d79508b166c66e07e4857e20233d85a9629913d6d79508b166c66e07e4857e20233d85a9
linuxlinux>= 4551236b55e80b2c1720b10b77e9400118b2339e < 38f72c7e7c6b55614f9407555fd5ce9d019b0fa438f72c7e7c6b55614f9407555fd5ce9d019b0fa4
linuxlinux>= 5.4.301 < 5.55.5
linuxlinux>= 66c8a83bf1de2eb3eea4734c7eda22255a965f11 < 81d0664bed91a858c7b50c263954b59d65f1b41481d0664bed91a858c7b50c263954b59d65f1b414
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 6.2 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.