cbcvebase.
CVE-2024-47751
published 2024-10-21

CVE-2024-47751: In the Linux kernel, the following vulnerability has been resolved: PCI: kirin: Fix buffer overflow in kirin_pcie_parse_port() Within kirin_pcie_parse_port()…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI: kirin: Fix buffer overflow in kirin_pcie_parse_port() Within kirin_pcie_parse_port(), the pcie->num_slots is compared to pcie->gpio_id_reset size (MAX_PCI_SLOTS) which is correct and would lead to an overflow. Thus, fix condition to pcie->num_slots + 1 >= MAX_PCI_SLOTS and move pcie->num_slots increment below the if-statement to avoid out-of-bounds array access. Found by Linux Verification Center (linuxtesting.org) with SVACE. [kwilczynski: commit log]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= b22dbbb24571c052364f476381dbac110bdca4d5 < a5f795f9412854df28e66679c5e6b68b0b79c229a5f795f9412854df28e66679c5e6b68b0b79c229
linuxlinux>= b22dbbb24571c052364f476381dbac110bdca4d5 < 95248d7497bcbfe7deed4805469c6ff6ddd7f9d195248d7497bcbfe7deed4805469c6ff6ddd7f9d1
linuxlinux>= b22dbbb24571c052364f476381dbac110bdca4d5 < 6dcc5b49d6607a741a14122bf3105f3ac50d259e6dcc5b49d6607a741a14122bf3105f3ac50d259e
linuxlinux>= b22dbbb24571c052364f476381dbac110bdca4d5 < aeb0335971806e15ac91e838ca471936c8e7efd5aeb0335971806e15ac91e838ca471936c8e7efd5
linuxlinux>= b22dbbb24571c052364f476381dbac110bdca4d5 < c500a86693a126c9393e602741e348f80f1b0fc5c500a86693a126c9393e602741e348f80f1b0fc5
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.26.11.2
linuxlinux_kernel>= 6.2 < 6.6.546.6.54
linuxlinux_kernel>= 6.7 < 6.10.136.10.13
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.