cbcvebase.
CVE-2024-50180
published 2024-11-08

CVE-2024-50180: In the Linux kernel, the following vulnerability has been resolved: fbdev: sisfb: Fix strbuf array overflow The values of the variables xres and yres are…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: fbdev: sisfb: Fix strbuf array overflow The values of the variables xres and yres are placed in strbuf. These variables are obtained from strbuf1. The strbuf1 array contains digit characters and a space if the array contains non-digit characters. Then, when executing sprintf(strbuf, "%ux%ux8", xres, yres); more than 16 bytes will be written to strbuf. It is suggested to increase the size of the strbuf array to 24. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 433c84c8495008922534c5cafdae6ff970fb3241433c84c8495008922534c5cafdae6ff970fb3241
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 57c4f4db0a194416da237fd09dad9527e00cb58757c4f4db0a194416da237fd09dad9527e00cb587
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 252f147b1826cbb30ae0304cf86b66d3bb12b743252f147b1826cbb30ae0304cf86b66d3bb12b743
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 41cf6f26abe4f491b694c54bd1aa2530369b751041cf6f26abe4f491b694c54bd1aa2530369b7510
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 889304120ecb2ca30674d89cd4ef15990b6a571c889304120ecb2ca30674d89cd4ef15990b6a571c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 688872c4ea4a528cd6a057d545c83506b533ee1f688872c4ea4a528cd6a057d545c83506b533ee1f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 11c0d49093b82f6c547fd419c41a982d26bdf5ef11c0d49093b82f6c547fd419c41a982d26bdf5ef
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9cf14f5a2746c19455ce9cb44341b5527b5e19c39cf14f5a2746c19455ce9cb44341b5527b5e19c3
linuxlinux_kernel< 4.19.3234.19.323
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 5.5 < 5.10.2275.10.227
linuxlinux_kernel>= 6.2 < 6.6.576.6.57

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.