cbcvebase.
CVE-2024-45008
published 2024-09-04

CVE-2024-45008: In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at input_mt_init_slots(), for num_slots is supplied from userspace using ioctl(UI_DEV_CREATE). Since nobody knows possible max slots, this patch chose 1024.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 2829c80614890624456337e47320289112785f3e2829c80614890624456337e47320289112785f3e
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 87f610a1a7fbdb1f2e3d90b54c955bd3b8a0c32287f610a1a7fbdb1f2e3d90b54c955bd3b8a0c322
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 05dd9aabd04f9b5eb04dab9bb83d8c3e982d754905dd9aabd04f9b5eb04dab9bb83d8c3e982d7549
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 95f73d01f547dfc67fda3022c51e377a0454b50595f73d01f547dfc67fda3022c51e377a0454b505
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 94736334b8a25e4fae8daa6934e54a31f099be4394736334b8a25e4fae8daa6934e54a31f099be43
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 8f04edd554d191834e9e1349ef030318ea6b11ba8f04edd554d191834e9e1349ef030318ea6b11ba
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < cd19f1799c32ba7b874474b1b968815ce5364f73cd19f1799c32ba7b874474b1b968815ce5364f73
linuxlinux>= 38e7afe96c7c0ad900824911c61fdb04078033dc < 99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb
linuxlinux_kernel< 4.19.3214.19.321
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 5.5 < 5.10.2255.10.225
linuxlinux_kernel>= 6.2 < 6.6.486.6.48

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.