cbcvebase.
CVE-2024-50131
published 2024-11-05

CVE-2024-50131: In the Linux kernel, the following vulnerability has been resolved: tracing: Consider the NULL character when validating the event length strlen() returns a…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing: Consider the NULL character when validating the event length strlen() returns a string length excluding the null byte. If the string length equals to the maximum buffer length, the buffer will have no space for the NULL terminating character. This commit checks this condition and returns failure for it.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < 5e3231b352725ff4a3a0095e6035af674f2d87255e3231b352725ff4a3a0095e6035af674f2d8725
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < 02874ca52df2ca2423ba6122039315ed61c2597202874ca52df2ca2423ba6122039315ed61c25972
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < b86b0d6eea204116e4185acc35041ca4ff11a642b86b0d6eea204116e4185acc35041ca4ff11a642
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < f4ed40d1c669bba1a54407d8182acdc405683f29f4ed40d1c669bba1a54407d8182acdc405683f29
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < a14a075a14af8d622c576145455702591bdde09da14a075a14af8d622c576145455702591bdde09d
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < 5fd942598ddeed9a212d1ff41f9f5b47bcc990a75fd942598ddeed9a212d1ff41f9f5b47bcc990a7
linuxlinux>= dec65d79fd269d05427c8167090bfc9c3d0b56c4 < 0b6e2e22cb23105fcb171ab92f0f7516c69c84710b6e2e22cb23105fcb171ab92f0f7516c69c8471
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.1 < 5.15.1705.15.170
linuxlinux_kernel>= 5.16 < 6.1.1156.1.115
linuxlinux_kernel>= 6.2 < 6.6.596.6.59
linuxlinux_kernel>= 6.7 < 6.11.66.11.6
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.