cbcvebase.
CVE-2024-47697
published 2024-10-21

CVE-2024-47697: In the Linux kernel, the following vulnerability has been resolved: drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error Ensure index in…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error Ensure index in rtl2830_pid_filter does not exceed 31 to prevent out-of-bounds access. dev->filters is a 32-bit value, so set_bit and clear_bit functions should only operate on indices from 0 to 31. If index is 32, it will attempt to access a non-existent 33rd bit, leading to out-of-bounds access. Change the boundary check from index > 32 to index >= 32 to resolve this issue.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 8ffbe7d07b8e76193b151107878ddc1ccc94deb58ffbe7d07b8e76193b151107878ddc1ccc94deb5
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 883f794c6e498ae24680aead55c16f66b06cfc30883f794c6e498ae24680aead55c16f66b06cfc30
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < badbd736e6649c4e6d7b4ff7e2b9857acfa9ea94badbd736e6649c4e6d7b4ff7e2b9857acfa9ea94
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 86d920d2600c3a48efc2775c1666c1017eec695686d920d2600c3a48efc2775c1666c1017eec6956
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 3dba83d3c81de1368d15a39f22df7b53e306052f3dba83d3c81de1368d15a39f22df7b53e306052f
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 58f31be7dfbc0c84a6497ad51924949cf64b86a258f31be7dfbc0c84a6497ad51924949cf64b86a2
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 7fd6aae7e53b94f4035b1bfce28b8dfa0d0ae4707fd6aae7e53b94f4035b1bfce28b8dfa0d0ae470
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 042b101d7bf70616c4967c286ffa6fcca65babfb042b101d7bf70616c4967c286ffa6fcca65babfb
linuxlinux>= df70ddad81b47c57bcccffc805fbd75f2f1b2dc6 < 46d7ebfe6a75a454a5fa28604f0ef1491f9d8d1446d7ebfe6a75a454a5fa28604f0ef1491f9d8d14
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.0 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.