cbcvebase.
CVE-2024-53106
published 2024-12-02

CVE-2024-53106: In the Linux kernel, the following vulnerability has been resolved: ima: fix buffer overrun in ima_eventdigest_init_common Function ima_eventdigest_init()…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ima: fix buffer overrun in ima_eventdigest_init_common Function ima_eventdigest_init() calls ima_eventdigest_init_common() with HASH_ALGO__LAST which is then used to access the array hash_digest_size[] leading to buffer overrun. Have a conditional statement to handle this.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 9fab303a2cb3d323ca3a32a8b4ab60b451141901 < e01aae58e818503f2ffcd34c6f7dc6f90af1057ee01aae58e818503f2ffcd34c6f7dc6f90af1057e
linuxlinux>= 9fab303a2cb3d323ca3a32a8b4ab60b451141901 < 8a84765c62cc0469864e2faee43aae253ad160828a84765c62cc0469864e2faee43aae253ad16082
linuxlinux>= 9fab303a2cb3d323ca3a32a8b4ab60b451141901 < 1ecf0df5205cfb0907eb7984b8671257965a52321ecf0df5205cfb0907eb7984b8671257965a5232
linuxlinux>= 9fab303a2cb3d323ca3a32a8b4ab60b451141901 < 923168a0631bc42fffd55087b337b1b6c54dcff5923168a0631bc42fffd55087b337b1b6c54dcff5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.19.1 < 6.1.1196.1.119
linuxlinux_kernel>= 6.2 < 6.6.636.6.63
linuxlinux_kernel>= 6.7 < 6.11.106.11.10

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.