CVE-2024-49984

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Prevent out of bounds access in performance query extensions Check that the number of perfmons userspace is passing in the copy and reset extensions is not greater than the internal kernel storage where the ids will be copied into.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

29 Oct 2024, 16:22

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/3e50d72abe50204c7b19784a66e86da29dde32c2 - () https://git.kernel.org/stable/c/3e50d72abe50204c7b19784a66e86da29dde32c2 - Patch
References () https://git.kernel.org/stable/c/73ad583bd4938bf37d2709fc36901eb6f22f2722 - () https://git.kernel.org/stable/c/73ad583bd4938bf37d2709fc36901eb6f22f2722 - Patch
References () https://git.kernel.org/stable/c/d9536f16be3970c170571efa707c13cd089c774e - () https://git.kernel.org/stable/c/d9536f16be3970c170571efa707c13cd089c774e - Patch
References () https://git.kernel.org/stable/c/f32b5128d2c440368b5bf3a7a356823e235caabb - () https://git.kernel.org/stable/c/f32b5128d2c440368b5bf3a7a356823e235caabb - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE CWE-787

23 Oct 2024, 15:13

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: drm/v3d: Evitar el acceso fuera de los límites en las extensiones de consulta de rendimiento. Compruebe que la cantidad de espacio de usuario de perfmons que pasa en las extensiones de copia y restablecimiento no sea mayor que el almacenamiento interno del kernel donde se copiarán los identificadores.

21 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-21 18:15

Updated : 2024-10-29 16:22


NVD link : CVE-2024-49984

Mitre link : CVE-2024-49984

CVE.ORG link : CVE-2024-49984


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write