cbcvebase.
CVE-2024-50195
published 2024-11-08

CVE-2024-50195: In the Linux kernel, the following vulnerability has been resolved: posix-clock: Fix missing timespec64 check in pc_clock_settime() As Andrew pointed out, it…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: posix-clock: Fix missing timespec64 check in pc_clock_settime() As Andrew pointed out, it will make sense that the PTP core checked timespec64 struct's tv_sec and tv_nsec range before calling ptp->info->settime64(). As the man manual of clock_settime() said, if tp.tv_sec is negative or tp.tv_nsec is outside the range [0..999,999,999], it should return EINVAL, which include dynamic clocks which handles PTP clock, and the condition is consistent with timespec64_valid(). As Thomas suggested, timespec64_valid() only check the timespec is valid, but not ensure that the time is in a valid range, so check it ahead using timespec64_valid_strict() in pc_clock_settime() and return -EINVAL if not valid. There are some drivers that use tp->tv_sec and tp->tv_nsec directly to write registers without validity checks and assume that the higher layer has checked it, which is dangerous and will benefit from this, such as hclge_ptp_settime(), igb_ptp_settime_i210(), _rcar_gen4_ptp_settime(), and some drivers can remove the checks of itself.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < 29f085345cde24566efb751f39e5d367c381c58429f085345cde24566efb751f39e5d367c381c584
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < e0c966bd3e31911b57ef76cec4c5796ebd88e512e0c966bd3e31911b57ef76cec4c5796ebd88e512
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < 673a1c5a2998acbd429d6286e6cad10f17f4f073673a1c5a2998acbd429d6286e6cad10f17f4f073
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < c8789fbe2bbf75845e45302cba6ffa44e1884d01c8789fbe2bbf75845e45302cba6ffa44e1884d01
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < 27abbde44b6e71ee3891de13e1a228aa7ce95bfe27abbde44b6e71ee3891de13e1a228aa7ce95bfe
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < a3f169e398215e71361774d13bf91a0101283ac2a3f169e398215e71361774d13bf91a0101283ac2
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < 1ff7247101af723731ea42ed565d54fb8f3412641ff7247101af723731ea42ed565d54fb8f341264
linuxlinux>= 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < d8794ac20a299b647ba9958f6d657051fc51a540d8794ac20a299b647ba9958f6d657051fc51a540
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-277.3114.4.0-277.311
linuxlinux_kernel>= 0 < 4.15.0-246.2584.15.0-246.258
linuxlinux_kernel>= 2.6.39 < 4.19.3234.19.323

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.