cbcvebase.
CVE-2024-47408
published 2025-01-11

CVE-2024-47408: In the Linux kernel, the following vulnerability has been resolved: net/smc: check smcd_v2_ext_offset when receiving proposal msg When receiving proposal msg…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net/smc: check smcd_v2_ext_offset when receiving proposal msg When receiving proposal msg in server, the field smcd_v2_ext_offset in proposal msg is from the remote client and can not be fully trusted. Once the value of smcd_v2_ext_offset exceed the max value, there has the chance to access wrong address, and crash may happen. This patch checks the value of smcd_v2_ext_offset before using it.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 5c21c4ccafe85906db809de3af391fd434df8a27 < a36364d8d4fabb105001f992fb8ff2d3546203d6a36364d8d4fabb105001f992fb8ff2d3546203d6
linuxlinux>= 5c21c4ccafe85906db809de3af391fd434df8a27 < e1cc8be2a785a8f1ce1f597f3e608602c5fccd46e1cc8be2a785a8f1ce1f597f3e608602c5fccd46
linuxlinux>= 5c21c4ccafe85906db809de3af391fd434df8a27 < 935caf324b445fe73d7708fae6f7176fb243f357935caf324b445fe73d7708fae6f7176fb243f357
linuxlinux>= 5c21c4ccafe85906db809de3af391fd434df8a27 < 48d5a8a304a643613dab376a278f29d3e22f7c3448d5a8a304a643613dab376a278f29d3e22f7c34
linuxlinux>= 5c21c4ccafe85906db809de3af391fd434df8a27 < 9ab332deb671d8f7e66d82a2ff2b3f715bc3a4ad9ab332deb671d8f7e66d82a2ff2b3f715bc3a4ad
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.10 < 5.15.1765.15.176
linuxlinux_kernel>= 5.16 < 6.1.1226.1.122
linuxlinux_kernel>= 6.2 < 6.6.686.6.68
linuxlinux_kernel>= 6.7 < 6.12.76.12.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.