cbcvebase.
CVE-2024-46859
published 2024-09-27

CVE-2024-46859: In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses The panasonic laptop…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses The panasonic laptop code in various places uses the SINF array with index values of 0 - SINF_CUR_BRIGHT(0x0d) without checking that the SINF array is big enough. Not all panasonic laptops have this many SINF array entries, for example the Toughbook CF-18 model only has 10 SINF array entries. So it only supports the AC+DC brightness entries and mute. Check that the SINF array has a minimum size which covers all AC+DC brightness entries and refuse to load if the SINF array is smaller. For higher SINF indexes hide the sysfs attributes when the SINF array does not contain an entry for that attribute, avoiding show()/store() accessing the array out of bounds and add bounds checking to the probe() and resume() code accessing these.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= e424fb8cc4e6634c10f8159b1ff5618cf7bab9c6 < b7c2f692307fe704be87ea80d7328782b33c3cefb7c2f692307fe704be87ea80d7328782b33c3cef
linuxlinux>= e424fb8cc4e6634c10f8159b1ff5618cf7bab9c6 < 9291fadbd2720a869b1d2fcf82305648e2e62a169291fadbd2720a869b1d2fcf82305648e2e62a16
linuxlinux>= e424fb8cc4e6634c10f8159b1ff5618cf7bab9c6 < 6821a82616f60aa72c5909b3e252ad97fb9f7e2a6821a82616f60aa72c5909b3e252ad97fb9f7e2a
linuxlinux>= e424fb8cc4e6634c10f8159b1ff5618cf7bab9c6 < b38c19783286a71693c2194ed1b36665168c09c4b38c19783286a71693c2194ed1b36665168c09c4
linuxlinux>= e424fb8cc4e6634c10f8159b1ff5618cf7bab9c6 < f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 3.3 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1116.1.111
linuxlinux_kernel>= 6.2 < 6.6.526.6.52
linuxlinux_kernel>= 6.7 < 6.10.116.10.11
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.