cbcvebase.
CVE-2024-44931
published 2024-08-26

CVE-2024-44931: In the Linux kernel, the following vulnerability has been resolved: gpio: prevent potential speculation leaks in gpio_device_get_desc() Userspace may trigger a…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: gpio: prevent potential speculation leaks in gpio_device_get_desc() Userspace may trigger a speculative read of an address outside the gpio descriptor array. Users can do that by calling gpio_ioctl() with an offset out of range. Offset is copied from user and then used as an array index to get the gpio descriptor without sanitization in gpio_device_get_desc(). This change ensures that the offset is sanitized by using array_index_nospec() to mitigate any possibility of speculative information leaks. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < 18504710442671b02d00e6db9804a0ad26c5a47918504710442671b02d00e6db9804a0ad26c5a479
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < 9ae2d8e75b741dbcb0da374753f972410e83b5f39ae2d8e75b741dbcb0da374753f972410e83b5f3
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < 9d682e89c44bd5819b01f3fbb45a8e3681a4b6d09d682e89c44bd5819b01f3fbb45a8e3681a4b6d0
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < c65ab97efcd438cb4e9f299400f2ea55251f3a67c65ab97efcd438cb4e9f299400f2ea55251f3a67
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < 672c19165fc96dfad531a5458e0b3cdab414aae4672c19165fc96dfad531a5458e0b3cdab414aae4
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < 1b955f786a4bcde8c0ccb2b7d519def2acb6f3cc1b955f786a4bcde8c0ccb2b7d519def2acb6f3cc
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < d776c0486b03a5c4afca65b8ff44573592bf93bbd776c0486b03a5c4afca65b8ff44573592bf93bb
linuxlinux>= 521a2ad6f862a28e2e43cb3e254a26bf0f9452e9 < d795848ecce24a75dfd46481aee066ae6fe39775d795848ecce24a75dfd46481aee066ae6fe39775
linuxlinux_kernel< 6.6.466.6.46
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 6.7 < 6.10.56.10.5
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.