cbcvebase.
CVE-2024-50268
published 2024-11-19

CVE-2024-50268: In the Linux kernel, the following vulnerability has been resolved: usb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd() The "*cmd"…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd() The "*cmd" variable can be controlled by the user via debugfs. That means "new_cam" can be as high as 255 while the size of the uc->updated[] array is UCSI_MAX_ALTMODES (30). The call tree is: ucsi_cmd() // val comes from simple_attr_write_xsigned() -> ucsi_send_command() -> ucsi_send_command_common() -> ucsi_run_command() // calls ucsi->ops->sync_control() -> ucsi_ccg_sync_control()

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 170a6726d0e266f2c8f306e3d61715c32f4ee41e < d76923164705821aa1b01b8d9d1741f20c654ab4d76923164705821aa1b01b8d9d1741f20c654ab4
linuxlinux>= 170a6726d0e266f2c8f306e3d61715c32f4ee41e < 8f47984b35f3be0cfc652c2ca358d5768ea3456b8f47984b35f3be0cfc652c2ca358d5768ea3456b
linuxlinux>= 170a6726d0e266f2c8f306e3d61715c32f4ee41e < 604314ecd682913925980dc955caea2d036eab5f604314ecd682913925980dc955caea2d036eab5f
linuxlinux>= 170a6726d0e266f2c8f306e3d61715c32f4ee41e < 69e19774f15e12dda6c6c58001d059e30895009b69e19774f15e12dda6c6c58001d059e30895009b
linuxlinux>= 170a6726d0e266f2c8f306e3d61715c32f4ee41e < 3a2ba841659a0f15102585120dea75d8d52096163a2ba841659a0f15102585120dea75d8d5209616
linuxlinux>= 170a6726d0e266f2c8f306e3d61715c32f4ee41e < 7dd08a0b4193087976db6b3ee7807de7e8316f967dd08a0b4193087976db6b3ee7807de7e8316f96
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.11 < 5.15.1725.15.172
linuxlinux_kernel>= 5.16 < 6.1.1176.1.117
linuxlinux_kernel>= 5.6 < 5.10.2305.10.230

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.