CVE-2024-49963Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux

Severity
5.5MEDIUMNVD
OSV8.8OSV6.7OSV6.3OSV4.7
EPSS
0.0%
top 98.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateDec 16

Description

In the Linux kernel, the following vulnerability has been resolved: mailbox: bcm2835: Fix timeout during suspend mode During noirq suspend phase the Raspberry Pi power driver suffer of firmware property timeouts. The reason is that the IRQ of the underlying BCM2835 mailbox is disabled and rpi_firmware_property_list() will always run into a timeout [1]. Since the VideoCore side isn't consider as a wakeup source, set the IRQF_NO_SUSPEND flag for the mailbox IRQ in order to keep it enabled durin

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages14 packages

Patches

🔴Vulnerability Details

41
OSV
linux-azure-fips vulnerabilities2025-12-16
OSV
linux-azure, linux-azure-4.15, linux-oracle, vulnerabilities2025-12-12
OSV
linux-gcp, linux-gcp-4.15, linux-hwe vulnerabilities2025-12-04
OSV
linux-gcp-fips vulnerabilities2025-12-04
OSV
linux-aws-fips, linux-fips vulnerabilities2025-12-03

📋Vendor Advisories

42
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-12-16
Ubuntu
Linux kernel kernel vulnerabilities2025-12-12
Ubuntu
Linux kernel vulnerabilities2025-12-04
Ubuntu
Linux kernel (GCP FIPS) vulnerabilities2025-12-04
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-12-03