cbcvebase.
CVE-2024-46774
published 2024-09-18

CVE-2024-46774: In the Linux kernel, the following vulnerability has been resolved: powerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas() Smatch warns…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.24%
15.4th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas() Smatch warns: arch/powerpc/kernel/rtas.c:1932 __do_sys_rtas() warn: potential spectre issue 'args.args' [r] (local cap) The 'nargs' and 'nret' locals come directly from a user-supplied buffer and are used as indexes into a small stack-based array and as inputs to copy_to_user() after they are subject to bounds checks. Use array_index_nospec() after the bounds checks to clamp these values for speculative execution.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d2834ff1d9641a8695a09ea79cd901c7b6d4d05fd2834ff1d9641a8695a09ea79cd901c7b6d4d05f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a262c2dc833f2fe1bd5c53a4d899e7077d3b1da9a262c2dc833f2fe1bd5c53a4d899e7077d3b1da9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b137af795399d8b657bad1646c18561530f35ed1b137af795399d8b657bad1646c18561530f35ed1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1f1feff02e9da0dd0cdb195c428c42b5f9b6c7711f1feff02e9da0dd0cdb195c428c42b5f9b6c771
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 68d8156480940b79227d58865ec5d2947b9384a868d8156480940b79227d58865ec5d2947b9384a8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0974d03eb479384466d828d65637814bee6b26d70974d03eb479384466d828d65637814bee6b26d7
linuxlinux_kernel< 6.10.106.10.10
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.