cbcvebase.
CVE-2024-57910
published 2025-01-19

CVE-2024-57910: In the Linux kernel, the following vulnerability has been resolved: iio: light: vcnl4035: fix information leak in triggered buffer The 'buffer' local array is…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
11.9th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: light: vcnl4035: fix information leak in triggered buffer The 'buffer' local array is used to push data to userspace from a triggered buffer, but it does not set an initial value for the single data element, which is an u16 aligned to 8 bytes. That leaves at least 4 bytes uninitialized even after writing an integer value with regmap_read(). Initialize the array to zero before using it to avoid pushing uninitialized information to userspace.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 49739675048d372946c1ef136c466d5675eba9f0 < b0e9c11c762e4286732d80e66c08c2cb3157b06bb0e9c11c762e4286732d80e66c08c2cb3157b06b
linuxlinux>= 5.10.50 < 5.10.2345.10.234
linuxlinux>= 5.12.17 < 5.135.13
linuxlinux>= 5.13.2 < 5.145.14
linuxlinux>= 5.4.132 < 5.4.2905.4.290
linuxlinux>= da8ef748fec2d55db0ae424ab40eee0c737564aa < 13e56229fc81051a42731046e200493c4a7c28ff13e56229fc81051a42731046e200493c4a7c28ff
linuxlinux>= ec90b52c07c0403a6db60d752484ec08d605ead0 < cb488706cdec0d6d13f2895bcdf0c32b283a7cc7cb488706cdec0d6d13f2895bcdf0c32b283a7cc7
linuxlinux>= ec90b52c07c0403a6db60d752484ec08d605ead0 < 47d245be86492974db3aeb048609542167f5651847d245be86492974db3aeb048609542167f56518
linuxlinux>= ec90b52c07c0403a6db60d752484ec08d605ead0 < a15ea87d4337479c9446b5d71616f4668337afeda15ea87d4337479c9446b5d71616f4668337afed
linuxlinux>= ec90b52c07c0403a6db60d752484ec08d605ead0 < f6fb1c59776b4263634c472a5be8204c906ffc2cf6fb1c59776b4263634c472a5be8204c906ffc2c
linuxlinux>= ec90b52c07c0403a6db60d752484ec08d605ead0 < 47b43e53c0a0edf5578d5d12f5fc71c01964927947b43e53c0a0edf5578d5d12f5fc71c019649279
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.10.50 < 5.10.2345.10.234

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.