cbcvebase.
CVE-2024-53158
published 2024-12-24

CVE-2024-53158: In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() This loop is supposed to…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() This loop is supposed to break if the frequency returned from clk_round_rate() is the same as on the previous iteration. However, that check doesn't make sense on the first iteration through the loop. It leads to reading before the start of these->clk_perf_tbl[] array.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < 37cdd4f0c266560b7b924c42361eeae3dc5f0c3e37cdd4f0c266560b7b924c42361eeae3dc5f0c3e
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < 7a3465b79ef0539aa10b310ac3cc35e0ae25b79e7a3465b79ef0539aa10b310ac3cc35e0ae25b79e
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < 748557ca7dc94695a6e209eb68fce365da9a3bb3748557ca7dc94695a6e209eb68fce365da9a3bb3
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < f4b7bf5a50f1fa25560f0b66a13563465542861bf4b7bf5a50f1fa25560f0b66a13563465542861b
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < b0a9c6ccaf88c4701787f61ecd2ec0eb014a0677b0a9c6ccaf88c4701787f61ecd2ec0eb014a0677
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < c24e019ca12d9ec814af04b30a64dd7173fb20fec24e019ca12d9ec814af04b30a64dd7173fb20fe
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < 56eda41dcce0ec4d3418b4f85037bdea181486cc56eda41dcce0ec4d3418b4f85037bdea181486cc
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < 351bb7f9ecb9d1f09bd7767491a2b8d07f4f1ea4351bb7f9ecb9d1f09bd7767491a2b8d07f4f1ea4
linuxlinux>= eddac5af06546d2e7a0730e3dc02dde3dc91098a < 78261cb08f06c93d362cab5c5034bf5899bc755278261cb08f06c93d362cab5c5034bf5899bc7552
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.18 < 4.19.3254.19.325
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.