cbcvebase.
CVE-2024-58069
published 2025-03-06

CVE-2024-58069: In the Linux kernel, the following vulnerability has been resolved: rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read The nvmem interface supports…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved: rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read The nvmem interface supports variable buffer sizes, while the regmap interface operates with fixed-size storage. If an nvmem client uses a buffer size less than 4 bytes, regmap_read will write out of bounds as it expects the buffer to point at an unsigned int. Fix this by using an intermediary unsigned int to hold the value.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < 21cd59fcb9952eb7505da2bdfc1eb9c619df3ff421cd59fcb9952eb7505da2bdfc1eb9c619df3ff4
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < 6f2a8ca9a0a38589f52a7f0fb9425b9ba987ae7c6f2a8ca9a0a38589f52a7f0fb9425b9ba987ae7c
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < e5536677da803ed54a29a446515c28dce7d3d574e5536677da803ed54a29a446515c28dce7d3d574
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < c72b7a474d3f445bf0c5bcf8ffed332c78eb28a1c72b7a474d3f445bf0c5bcf8ffed332c78eb28a1
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < 9adefa7b9559d0f21034a5d5ec1b55840c9348b99adefa7b9559d0f21034a5d5ec1b55840c9348b9
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < e5e06455760f2995b16a176033909347929d1128e5e06455760f2995b16a176033909347929d1128
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < 517aedb365f2c94e2d7e0b908ac7127df76203a1517aedb365f2c94e2d7e0b908ac7127df76203a1
linuxlinux>= fadfd092ee9138825d8c2a4f95719d2e2e3202b9 < 3ab8c5ed4f84fa20cd16794fe8dc31f633fbc70c3ab8c5ed4f84fa20cd16794fe8dc31f633fbc70c
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.2 < 5.4.2915.4.291
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.766.6.76
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.