cbcvebase.
CVE-2024-57907
published 2025-01-19

CVE-2024-57907: In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in triggered buffer The 'data' local struct…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
11.4th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in triggered buffer The 'data' local struct is used to push data to user space from a triggered buffer, but it does not set values for inactive channels, as it only uses iio_for_each_active_channel() to assign new values. Initialize the struct to zero before using it to avoid pushing uninitialized information to userspace.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 4e130dc7b41348b13684f0758c26cc6cf72a3449 < 85a9c98a5e0f22d911b00077d751e34fff1401aa85a9c98a5e0f22d911b00077d751e34fff1401aa
linuxlinux>= 4e130dc7b41348b13684f0758c26cc6cf72a3449 < 7a07fb80ea886e9134284a27d0155cca7649e2937a07fb80ea886e9134284a27d0155cca7649e293
linuxlinux>= 4e130dc7b41348b13684f0758c26cc6cf72a3449 < 64b79afdca7b27a768c7d3716b7f4deb1d6b955c64b79afdca7b27a768c7d3716b7f4deb1d6b955c
linuxlinux>= 4e130dc7b41348b13684f0758c26cc6cf72a3449 < 5a95fbbecec7a34bbad5dcc3156700b8711d53c45a95fbbecec7a34bbad5dcc3156700b8711d53c4
linuxlinux>= 4e130dc7b41348b13684f0758c26cc6cf72a3449 < 8193941bc4fe7247ff13233f328aea709f5745548193941bc4fe7247ff13233f328aea709f574554
linuxlinux>= 4e130dc7b41348b13684f0758c26cc6cf72a3449 < 38724591364e1e3b278b4053f102b49ea06ee17c38724591364e1e3b278b4053f102b49ea06ee17c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.9 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.